Lucene search

K
cveIbmCVE-2013-0565
HistoryApr 24, 2013 - 10:28 a.m.

CVE-2013-0565

2013-04-2410:28:37
CWE-79
ibm
web.nvd.nist.gov
39
ibm
websphere
xss
rpc
vulnerability
security
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

7.3

Confidence

High

EPSS

0.002

Percentile

55.1%

Cross-site scripting (XSS) vulnerability in the RPC adapter for the Web 2.0 and Mobile toolkit in IBM WebSphere Application Server (WAS) 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted response.

Affected configurations

Nvd
Node
ibmwebsphere_application_serverMatch8.5.0.0
OR
ibmwebsphere_application_serverMatch8.5.0.1
VendorProductVersionCPE
ibmwebsphere_application_server8.5.0.0cpe:2.3:a:ibm:websphere_application_server:8.5.0.0:*:*:*:*:*:*:*
ibmwebsphere_application_server8.5.0.1cpe:2.3:a:ibm:websphere_application_server:8.5.0.1:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

7.3

Confidence

High

EPSS

0.002

Percentile

55.1%

Related for CVE-2013-0565