Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote attackers to inject arbitrary web script or HTML via HTTP response data.
https://exchange.xforce.ibmcloud.com/vulnerabilities/87479
http://www.securityfocus.com/bid/63780
http://www-01.ibm.com/support/docview.wss?uid=swg1PM93944