PT-2013-2433 · Ibm · Ibm Document Connect For Application Support Facility
Published
2013-04-27
·
Updated
2017-08-29
·
CVE-2013-0571
CVSS v2.0
2.9
Low
| Vector | AV:A/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Document Connect for Application Support Facility (DC4ASF) version 1.0.0.1217 and earlier
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via a crafted URL. This can be exploited by sending a malicious URL to the victim.
Recommendations
For versions 1.0.0.1217 and earlier, update to version 1.0.0.1218 or later to resolve the issue. As a temporary workaround, consider restricting access to the DC4ASF application until the update is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Document Connect For Application Support Facility