First published: Mon Apr 01 2013(Updated: )
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server 8.1, 8.5 through FP3, 8.7 through FP2, and 9.1 allows remote attackers to inject arbitrary web script or HTML via a malformed URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Information Server | =8.1 | |
IBM InfoSphere Information Server | =8.5 | |
IBM InfoSphere Information Server | =8.5.0.1 | |
IBM InfoSphere Information Server | =8.5.0.2 | |
IBM InfoSphere Information Server | =8.5.0.3 | |
IBM InfoSphere Information Server | =8.7 | |
IBM InfoSphere Information Server | =8.7.0.1 | |
IBM InfoSphere Information Server | =8.7.0.2 | |
IBM InfoSphere Information Server | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0502 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2013-0502, upgrade your IBM InfoSphere Information Server to a version that is not affected by this vulnerability.
CVE-2013-0502 affects IBM InfoSphere Information Server versions 8.1, 8.5 (through FP3), 8.7 (through FP2), and 9.1.
CVE-2013-0502 can be exploited by attackers to perform cross-site scripting (XSS) attacks.
Mitigation for CVE-2013-0502 is limited, and the best approach is to update to a safe version of the software.