Lucene search

K
cve[email protected]CVE-2013-0186
HistoryNov 01, 2019 - 7:15 p.m.

CVE-2013-0186

2019-11-0119:15:10
CWE-79
web.nvd.nist.gov
154
cve-2013-0186
manageiq
evm
cross-site scripting
xss
vulnerabilities
web script
html
remote attackers
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

39.5%

Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected configurations

Vulners
NVD
Node
redhatcloudforms_3.0_management_engineRange3.05.2
VendorProductVersionCPE
redhatcloudforms_3\.0_management_engine*cpe:2.3:a:redhat:cloudforms_3\.0_management_engine:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "ManageIQ EVM",
    "vendor": "ManageIQ EVM",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  },
  {
    "product": "Red Hat CloudForms 3.0",
    "vendor": "Red Hat",
    "versions": [
      {
        "status": "affected",
        "version": "Red Hat CloudForms 3.0 Management Engine 5.2"
      }
    ]
  }
]

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

39.5%

Related for CVE-2013-0186