CVE-2009-0855
Description
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cross-site scripting vulnerability in IBM WebSphere Application Server 6.1 (z/OS) administrative console allows injection of arbitrary web script or HTML.
Vulnerability
A cross-site scripting (XSS) vulnerability exists in the administrative console of IBM WebSphere Application Server (WAS) 6.1 for z/OS prior to version 6.1.0.23. The vulnerability allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. The issue is addressed by APAR PK81212, which is part of Fix Pack 6.1.0.23 (H28W610). [1][2]
Exploitation
An attacker can exploit this vulnerability remotely without authentication by crafting a malicious input that is not properly sanitized by the administrative console. The unspecified vectors suggest that user interaction may be required, such as a victim with administrative console access clicking on a crafted link or viewing a malicious page. The attacker does not need prior privileges or access to the system other than network connectivity. [1][2]
Impact
Successful exploitation allows an attacker to execute arbitrary web script or HTML in the context of the victim's browser session within the administrative console. This can lead to information disclosure (e.g., session tokens, configuration data), defacement, or actions performed on behalf of the victim administrator. The impact is limited to the browser session and does not grant direct server-side control. [1][2]
Mitigation
IBM released a fix as part of APAR PK81212, included in WebSphere Application Server V6.1.0.23 for z/OS (Fix Pack H28W610). Users should upgrade to version 6.1.0.23 or later. No workarounds are documented in the available references. [1][2]
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
26cpe:2.3:a:ibm:websphere_application_server:6.1:*:*:*:*:*:*:*+ 25 more
- cpe:2.3:a:ibm:websphere_application_server:6.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.15:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.16:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.17:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.18:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.19:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.20:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.21:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.22:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.1.0.9:*:*:*:*:*:*:*
- (no CPE)range: <6.1.0.23
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- secunia.com/advisories/34131nvdVendor Advisory
- www-01.ibm.com/support/docview.wssnvdVendor Advisory
- www-01.ibm.com/support/docview.wssnvdVendor Advisory
- www.vupen.com/english/advisories/2009/0607nvdVendor Advisory
- packetstormsecurity.com/files/170073/IBM-Websphere-Application-Server-7.0-Cross-Site-Scripting.htmlnvd
- secunia.com/advisories/34461nvd
- www-01.ibm.com/support/docview.wssnvd
- www.securityfocus.com/bid/34001nvd
- www.securityfocus.com/bid/34259nvd
- www.vupen.com/english/advisories/2009/0854nvd
News mentions
0No linked articles in our index yet.