CVE-2013-6323
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, and WebSphere Virtual Enterprise 7.x before 7.0.0.5, allows remote…
Does this matter?
Lower severity and a low EPSS score (1.61%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, and WebSphere Virtual Enterprise 7.x before 7.0.0.5, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
- EPSS
- 1.61% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- ibm/websphere virtual enterprise · ibm/websphere application server
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI04777
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI04880
- http://www-01.ibm.com/support/docview.wss?uid=swg21669554Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676091Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676092Vendor Advisory
- http://www.securityfocus.com/bid/67720
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88903
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI04777
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI04880
- http://www-01.ibm.com/support/docview.wss?uid=swg21669554Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676091Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676092Vendor Advisory
- http://www.securityfocus.com/bid/67720
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88903
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.