PT-2014-1404 · Ibm · Ibm Smartcloud Analytics Log Analysis
Published
2014-04-24
·
Updated
2017-08-29
·
CVE-2013-6738
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM SmartCloud Analytics Log Analysis versions 1.1 through 1.2 before 1.2.0.0-CSI-SCALA-IF0003
Description
The issue allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint, specifically the
OAuth authorization endpoint. This is a cross-site scripting (XSS) vulnerability.Recommendations
For versions 1.1 through 1.2 before 1.2.0.0-CSI-SCALA-IF0003, update to version 1.2.0.0-CSI-SCALA-IF0003 or later to resolve the issue.
As a temporary workaround, consider restricting access to the OAuth authorization endpoint to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Smartcloud Analytics Log Analysis