{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"les versions d'IBM WebSphere Edge Server ant\u00e9rieures \u00e0 5.1.1.38.","product":{"name":"WebSphere","vendor":{"name":"IBM","scada":false}}},{"description":"les versions d'IBM WebSphere Edge Server ant\u00e9rieures \u00e0 6.0.2.26 ;","product":{"name":"WebSphere","vendor":{"name":"IBM","scada":false}}},{"description":"les versions d'IBM WebSphere Edge Server ant\u00e9rieures \u00e0 6.1.0.15 ;","product":{"name":"WebSphere","vendor":{"name":"IBM","scada":false}}}],"affected_systems_content":null,"content":"## Description\n\nUne vuln\u00e9rabilit\u00e9 de type injection de code indirecte (XSS) a \u00e9t\u00e9\nidentifi\u00e9e dans IBM WebSphere Edge Server. Elle concerne les r\u00e8gles\nd'association CGI (CGI mapping rules) associ\u00e9es \u00e0 un message d'erreur.\n\n## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[],"links":[{"title":"Bulletin de s\u00e9curit\u00e9 IBM swg21294776 du 05 f\u00e9vrier 2008 :","url":"http://www-1.ibm.com/support/docview.wss?uid=swg21294776"}],"reference":"CERTA-2008-AVI-058","revisions":[{"description":"version initiale.","revision_date":"2008-02-07T00:00:00.000000"}],"risks":[{"description":"Atteinte \u00e0 l'int\u00e9grit\u00e9 des donn\u00e9es"},{"description":"Contournement de la politique de s\u00e9curit\u00e9"},{"description":"Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"}],"summary":"Une vuln\u00e9rabilit\u00e9 de type injection de code indirecte (XSS) a \u00e9t\u00e9\nidentifi\u00e9e dans IBM WebSphere Edge Server.\n","title":"Vuln\u00e9rabilit\u00e9 dans IBM WebSphere Edge Server","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 IBM 1294776 du 05 f\u00e9vrier 2008","url":null}]}
