CVE-2013-3979: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Web\Content\Help\ in the Web Client in IBM Cognos Command Center (aka Star Command Center or Star Analytics) before 10.1, when Internet Explorer is used, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3979?
CVE-2013-3979 has a medium severity level due to multiple XSS vulnerabilities that may allow an attacker to inject malicious scripts.
How do I fix CVE-2013-3979?
To fix CVE-2013-3979, update to a patched version of IBM Cognos Command Center that addresses the XSS vulnerabilities.
Who is affected by CVE-2013-3979?
CVE-2013-3979 affects users of IBM Cognos Command Center versions prior to 10.1 when using Internet Explorer.
What types of attacks can CVE-2013-3979 facilitate?
CVE-2013-3979 can facilitate cross-site scripting (XSS) attacks, allowing remote authenticated users to execute arbitrary web scripts.
Is Internet Explorer vulnerable due to CVE-2013-3979?
No, Internet Explorer itself is not vulnerable, but the XSS vulnerabilities in IBM Cognos Command Center when used with it can be exploited.