PT-2014-1404 · Ibm · Ibm Smartcloud Analytics Log Analysis

Published

2014-04-24

·

Updated

2017-08-29

·

CVE-2013-6738

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM SmartCloud Analytics Log Analysis versions 1.1 through 1.2 before 1.2.0.0-CSI-SCALA-IF0003
Description The issue allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint, specifically the OAuth authorization endpoint. This is a cross-site scripting (XSS) vulnerability.
Recommendations For versions 1.1 through 1.2 before 1.2.0.0-CSI-SCALA-IF0003, update to version 1.2.0.0-CSI-SCALA-IF0003 or later to resolve the issue. As a temporary workaround, consider restricting access to the OAuth authorization endpoint to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00355
CVE-2013-6738

Affected Products

Ibm Smartcloud Analytics Log Analysis