CVE-2013-0576
Cross-site scripting (XSS) vulnerability in the Tivoli Enterprise Portal browser client in IBM Tivoli Monitoring 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP02 allows remote attackers to inject arbitrary web script or…
Does this matter?
Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the Tivoli Enterprise Portal browser client in IBM Tivoli Monitoring 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.15% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- ibm/tivoli monitoring
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV32812
- http://www-01.ibm.com/support/docview.wss?uid=swg21634920Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83328
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV32812
- http://www-01.ibm.com/support/docview.wss?uid=swg21634920Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83328
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.