Lucene search

K
cve[email protected]CVE-2014-0913
HistoryMay 09, 2014 - 1:55 a.m.

CVE-2014-0913

2014-05-0901:55:02
CWE-79
web.nvd.nist.gov
35
2
ibm
inotes
domino
xss
vulnerability
email
nvd
security

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.6 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.1%

Cross-site scripting (XSS) vulnerability in IBM iNotes and Domino 8.5.3 FP6 before IF2 and 9.0.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via an e-mail message, aka SPR BFEY9GXHZE.

Affected configurations

NVD
Node
ibmlotus_dominoMatch8.5.3.6
OR
ibmlotus_dominoMatch9.0.1.0
OR
ibmlotus_inotesMatch8.5.3.6
OR
ibmlotus_inotesMatch9.0.1.0

Social References

More

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.6 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.1%