Lucene search

K
cve[email protected]CVE-2013-0506
HistoryMar 19, 2013 - 6:55 p.m.

CVE-2013-0506

2013-03-1918:55:03
CWE-79
web.nvd.nist.gov
26
ibm
sterling order management
xss
vulnerability
ibm sterling
web script
html
nvd
cve-2013-0506

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.2 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.1%

Cross-site scripting (XSS) vulnerability in IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Affected configurations

NVD
Node
ibmsterling_multi-channel_fulfillment_solutionMatch8.0
OR
ibmsterling_selling_and_fulfillment_foundationMatch8.5
OR
ibmsterling_selling_and_fulfillment_foundationMatch9.0
OR
ibmsterling_selling_and_fulfillment_foundationMatch9.1.0
OR
ibmsterling_selling_and_fulfillment_foundationMatch9.2.0

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.2 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.1%

Related for CVE-2013-0506