VulnerabilityModified
CVE-2013-5438
Cross-site scripting (XSS) vulnerability in the web server in IBM Flex System Manager (FSM) 1.1.0 through 1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
MEDIUM 4.3EPSS 1.77%
Does this matter?
Lower severity and a low EPSS score (1.77%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the web server in IBM Flex System Manager (FSM) 1.1.0 through 1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.77% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- ibm/flex system manager
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_flex_system_manager_web_server_allows_generic_xss_cve_2013_5438Vendor Advisory
- http://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5094212Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87753
- http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_flex_system_manager_web_server_allows_generic_xss_cve_2013_5438Vendor Advisory
- http://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5094212Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87753
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.