CVE-2013-0585: XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to the (1) web console and (2) repository management user interfaces.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0585?
CVE-2013-0585 has a medium severity rating due to its cross-site scripting (XSS) vulnerabilities that allow remote authenticated users to inject scripts.
How do I fix CVE-2013-0585?
To fix CVE-2013-0585, upgrade to a patched version of IBM InfoSphere Information Server that resolves these XSS vulnerabilities.
Which versions of IBM InfoSphere Information Server are affected by CVE-2013-0585?
CVE-2013-0585 affects IBM InfoSphere Information Server versions 8.1, 8.5, 8.7, and 9.1 up to their specified fix packs.
What are the attack vectors for CVE-2013-0585?
The attack vectors for CVE-2013-0585 are related to the web console and repository management user interfaces.
Can remote users exploit CVE-2013-0585?
Yes, remote authenticated users can exploit CVE-2013-0585 to inject arbitrary web scripts or HTML into affected systems.