Vulnerability Bulletins

IBM Security Bulletin: Potential XSS vulnerability in applications developed with Web Experience Factory, WebSphere Dashboard Framework, and Lotus Widget Factory.

   
Affected software IBM
 
Customer applications developed with Web Experience Factory, WebSphere Dashboard Framework, or Lotus Widget Factory may contain an XSS vulnerability caused by a failure to properly encode a value written to a page. The vulnerability is only present in applications that use Dojo builders and have enabled a specific, but uncommon, WebSphere Portal feature. CVE(s): CVE-2014-6196 Affected product(s) and affected version(s): All versions of Web Experience Factory, WebSphere Dashboard Framework,

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_potential_xss_vulnerability_in_applications_developed_with_web_experience_factory_websphere_dashboard_framework_and_lotus_widget_factory?lang=en_us