4.3
CVE-2013-0499
- EPSS 0.26%
- Veröffentlicht 28.05.2013 16:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle psirt@us.ibm.com
- Teams Watchlist Login
- Unerledigt Login
Cross-site scripting (XSS) vulnerability in the echo functionality on IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0, 4.0.1, 4.0.2, and 5.0.0 allows remote attackers to inject arbitrary web script or HTML via a SOAP message, as demonstrated by the XML Firewall, Multi Protocol Gateway (MPGW), Web Service Proxy, and Web Token services.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Websphere Datapower Xc10 Appliance Firmware Version3.8.2
Ibm ≫ Websphere Datapower Xc10 Appliance Firmware Version4.0
Ibm ≫ Websphere Datapower Xc10 Appliance Firmware Version4.0.1
Ibm ≫ Websphere Datapower Xc10 Appliance Firmware Version4.0.2
Ibm ≫ Websphere Datapower Xc10 Appliance Firmware Version5.0.0
Ibm ≫ Websphere Datapower Xc10 Appliance Version-
Ibm ≫ Websphere Datapower Service Gateway Xg45 Firmware Version3.8.2
Ibm ≫ Websphere Datapower Service Gateway Xg45 Firmware Version4.0
Ibm ≫ Websphere Datapower Service Gateway Xg45 Firmware Version4.0.1
Ibm ≫ Websphere Datapower Service Gateway Xg45 Firmware Version4.0.2
Ibm ≫ Websphere Datapower Service Gateway Xg45 Firmware Version5.0.0
Ibm ≫ Websphere Datapower Service Gateway Xg45 Version-
Ibm ≫ Websphere Datapower Integration Appliance Xi52 Firmware Version3.8.2
Ibm ≫ Websphere Datapower Integration Appliance Xi52 Firmware Version4.0.1
Ibm ≫ Websphere Datapower Integration Appliance Xi52 Firmware Version4.0.2
Ibm ≫ Websphere Datapower Integration Appliance Xi52 Firmware Version5.0.0
Ibm ≫ Websphere Datapower Integration Appliance Xi50 Firmware Version3.8.2
Ibm ≫ Websphere Datapower Integration Appliance Xi50 Firmware Version4.0.1
Ibm ≫ Websphere Datapower Integration Appliance Xi50 Firmware Version4.0.2
Ibm ≫ Websphere Datapower Integration Appliance Xi50 Firmware Version5.0.0
Ibm ≫ Websphere Datapower B2b Appliance Xb62 Firmware Version3.8.2
Ibm ≫ Websphere Datapower B2b Appliance Xb62 Firmware Version4.0
Ibm ≫ Websphere Datapower B2b Appliance Xb62 Firmware Version4.0.1
Ibm ≫ Websphere Datapower B2b Appliance Xb62 Firmware Version4.0.2
Ibm ≫ Websphere Datapower B2b Appliance Xb62 Firmware Version5.0.0
Ibm ≫ Websphere Datapower B2b Appliance Xb62 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.26% | 0.461 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.