PT-2014-1404 · Ibm · Ibm Smartcloud Analytics Log Analysis
Publicado
2014-04-24
·
Atualizado
2017-08-29
·
CVE-2013-6738
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM SmartCloud Analytics Log Analysis versions 1.1 through 1.2 before 1.2.0.0-CSI-SCALA-IF0003
Description
The issue allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint, specifically the
OAuth authorization endpoint. This is a cross-site scripting (XSS) vulnerability.Recommendations
For versions 1.1 through 1.2 before 1.2.0.0-CSI-SCALA-IF0003, update to version 1.2.0.0-CSI-SCALA-IF0003 or later to resolve the issue.
As a temporary workaround, consider restricting access to the OAuth authorization endpoint to minimize the risk of exploitation.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Smartcloud Analytics Log Analysis