First published: Sat Apr 27 2013(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Document Connect for Application Support Facility (aka DC4ASF) before 1.0.0.1218 in Application Support Facility (ASF) 3.4 for z/OS on Windows, Linux, and AIX allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Application Support Facility | =3.4.0 | |
IBM Application Support Facility | =3.4.0 | |
IBM Application Support Facility | =3.4.0 | |
IBM Application Support Facility | =3.4.0 | |
IBM Document Connect for Application Support Facility | <=1.0.0.1204 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0571 is classified as a moderate severity vulnerability due to its potential for exploitation via cross-site scripting.
To fix CVE-2013-0571, update IBM Document Connect for Application Support Facility to version 1.0.0.1218 or later.
CVE-2013-0571 affects IBM Application Support Facility version 3.4.0 on platforms including AIX, Linux, Windows, and z/OS.
CVE-2013-0571 allows remote attackers to execute cross-site scripting attacks by injecting arbitrary web scripts or HTML.
Yes, specifically upgrading to IBM Document Connect for Application Support Facility version 1.0.0.1218 is necessary to mitigate CVE-2013-0571.