Back

CVE-2001-0824

Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.

Published: Dec 6, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
ibm websphere_application_server 3.0.2
ibm websphere_application_server 3.5

GitHub Security Advisory GHSA-fj7j-6rv7-xjr4

Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.27%

Top 19% most likely to be exploited

Threat Score 30.7 / 100

Data Sources

NVD EPSS GitHub