PT-2014-1404 · Ibm · Ibm Smartcloud Analytics Log Analysis

Publicado

2014-04-24

·

Atualizado

2017-08-29

·

CVE-2013-6738

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM SmartCloud Analytics Log Analysis versions 1.1 through 1.2 before 1.2.0.0-CSI-SCALA-IF0003
Description The issue allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint, specifically the OAuth authorization endpoint. This is a cross-site scripting (XSS) vulnerability.
Recommendations For versions 1.1 through 1.2 before 1.2.0.0-CSI-SCALA-IF0003, update to version 1.2.0.0-CSI-SCALA-IF0003 or later to resolve the issue. As a temporary workaround, consider restricting access to the OAuth authorization endpoint to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00355
CVE-2013-6738

Produtos afetados

Ibm Smartcloud Analytics Log Analysis