Vulnerability Bulletins

IBM Security Bulletin: Reflected and Persistent cross-site scripting vulnerabilities found in WebSphere Commerce (CVE-2015-5008, CVE-2015-5009)

   
Affected software IBM
 
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer is vulnerable to reflected and persistent cross-site scripting, caused by improper validation of user-supplied input. The following are affected: Aurora starter store, Commerce Management Center, Accelerator, Organization Administration Console. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victims Web browser within the security context of the hosting Web site, once

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_reflected_and_persistent_cross_site_scripting_vulnerabilities_found_in_websphere_commerce_cve_2015_5008_cve_2015_5009?lang=en_us