PT-2013-2388 · Ibm · Ibm Infosphere Information Server

Published

2013-04-01

·

Updated

2017-08-29

·

CVE-2013-0502

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM InfoSphere Information Server versions 8.1, 8.5 through FP3, 8.7 through FP2, and 9.1
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via a malformed URL. This could potentially lead to unauthorized access or control of user sessions.
Recommendations For version 8.1, update to a fixed version to resolve the issue. For versions 8.5 through FP3, apply the necessary fixes or updates to address the vulnerability. For versions 8.7 through FP2, update to a version later than FP2 to mitigate the risk. For version 9.1, apply the recommended patch or update to fix the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-0502

Affected Products

Ibm Infosphere Information Server