Lucene search

K
ibmIBMFE9FDA9C293C771D83326A84EA1C01C79E032BAB2844A77207FED0265BF49662
HistorySep 25, 2022 - 9:06 p.m.

Security Bulletin: Informix Open Admin Tool (OAT) cross-site scripting vulnerability (CVE-2013-0492)

2022-09-2521:06:56
www.ibm.com
10
informix open admin tool
cross-site scripting
vulnerability
mal-formed urls
unauthorized access
sensitive information
cve-2013-0492
security bulletin
ibm security

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

26.5%

Abstract

An attacker can trick a user into inserting a mal-formed URL address into a browser or clicking on a mal-formed URL link and exploit a cross-site scripting vulnerability that can be used to gain unauthorized access or collect sensitive information.

Content

CVEID: CVE-2013-0492

CVSS Base Score: 3.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/82007 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

AFFECTED PRODUCTS AND VERSIONS:
Informix Open Admin Tool (OAT) 3.11 and prior releases

REMEDIATION:

**_Fix(es):
_**Upgrade to OAT 3.11.1 or later:
https://www14.software.ibm.com/webapp/iwm/web/reg/download.do?source=swg-informixfpd&lang=en_US&S_PKG=dl&cp=UTF-8

Workaround(s):
None

Mitigation(s):
None

REFERENCES:

ยท Complete CVSS Guide
ยท On-line Calculator V2
ยท CVE-2013-0492
ยท X-Force Vulnerability Database_ _

RELATED INFORMATION:
_IBM Secure Engineering Web Portal _
IBM Product Security Incident Response Blog

ACKNOWLEDGEMENT
None

CHANGE HISTORY
August 8, 2013: Original version published

_*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Flash. _

_Note: _According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an โ€œindustry open standard designed to convey vulnerability severity and help to determine urgency and priority of response.โ€ IBM PROVIDES THE CVSS SCORES โ€œAS ISโ€ WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

[{โ€œProductโ€:{โ€œcodeโ€:โ€œSSVT2Jโ€,โ€œlabelโ€:โ€œInformix Toolsโ€},โ€œBusiness Unitโ€:{โ€œcodeโ€:โ€œBU059โ€,โ€œlabelโ€:โ€œIBM Software w/o TPSโ€},โ€œComponentโ€:โ€œโ€“โ€,โ€œPlatformโ€:[{โ€œcodeโ€:โ€œPF002โ€,โ€œlabelโ€:โ€œAIXโ€},{โ€œcodeโ€:โ€œPF010โ€,โ€œlabelโ€:โ€œHP-UXโ€},{โ€œcodeโ€:โ€œPF016โ€,โ€œlabelโ€:โ€œLinuxโ€},{โ€œcodeโ€:โ€œPF022โ€,โ€œlabelโ€:โ€œOS Xโ€},{โ€œcodeโ€:โ€œPF027โ€,โ€œlabelโ€:โ€œSolarisโ€},{โ€œcodeโ€:โ€œPF033โ€,โ€œlabelโ€:โ€œWindowsโ€}],โ€œVersionโ€:โ€œ2.0;3.0โ€,โ€œEditionโ€:โ€œโ€,โ€œLine of Businessโ€:{โ€œcodeโ€:โ€œLOB10โ€,โ€œlabelโ€:โ€œData and AIโ€}}]

Affected configurations

Vulners
Node
ibminformix_jdbcMatch2.0
OR
ibminformix_jdbcMatch3.0
VendorProductVersionCPE
ibminformix_jdbc2.0cpe:2.3:a:ibm:informix_jdbc:2.0:*:*:*:*:*:*:*
ibminformix_jdbc3.0cpe:2.3:a:ibm:informix_jdbc:3.0:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

26.5%

Related for FE9FDA9C293C771D83326A84EA1C01C79E032BAB2844A77207FED0265BF49662