First published: Wed Feb 20 2013(Updated: )
Cross-site scripting (XSS) vulnerability in IBM WebSphere Message Broker 7.0 before 7.0.0.6 and 8.0 before 8.0.0.2, when wsdl support is enabled on a SOAPInput node, allows remote attackers to inject arbitrary web script or HTML via a wsdl request that is not properly handled during construction of an error message.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Message Broker | =7.0. | |
IBM WebSphere Message Broker | =7.0.0.1 | |
IBM WebSphere Message Broker | =7.0.0.2 | |
IBM WebSphere Message Broker | =7.0.0.3 | |
IBM WebSphere Message Broker | =7.0.0.4 | |
IBM WebSphere Message Broker | =7.0.0.5 | |
IBM WebSphere Message Broker | =8.0 | |
IBM WebSphere Message Broker | =8.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0466 is rated as Important due to the potential for remote code execution via cross-site scripting (XSS).
To fix CVE-2013-0466, upgrade IBM WebSphere Message Broker to versions 7.0.0.6 or 8.0.0.2 or later, where the issue has been resolved.
Affected versions include IBM WebSphere Message Broker 7.0 before 7.0.0.6 and 8.0 before 8.0.0.2.
CVE-2013-0466 is a cross-site scripting (XSS) vulnerability that allows attackers to inject scripts into web pages.
Remote attackers can exploit CVE-2013-0466 to inject arbitrary web scripts or HTML, affecting users of the targeted applications.