First published: Thu Jul 25 2013(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Web\Content\Help\ in the Web Client in IBM Cognos Command Center (aka Star Command Center or Star Analytics) before 10.1, when Internet Explorer is used, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Star Command Center | =1.6.1 | |
IBM Star Command Center | =3.0.0 | |
IBM Star Command Center | =3.0.1 | |
IBM Star Command Center | =3.0.2 | |
IBM Star Command Center | =3.0.3 | |
IBM Star Command Center | =3.0.4 | |
IBM Star Command Center | =3.0.5 | |
IBM Star Command Center | =3.0.6 | |
IBM Star Command Center | =3.0.7 | |
Internet Explorer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3979 has a medium severity level due to multiple XSS vulnerabilities that may allow an attacker to inject malicious scripts.
To fix CVE-2013-3979, update to a patched version of IBM Cognos Command Center that addresses the XSS vulnerabilities.
CVE-2013-3979 affects users of IBM Cognos Command Center versions prior to 10.1 when using Internet Explorer.
CVE-2013-3979 can facilitate cross-site scripting (XSS) attacks, allowing remote authenticated users to execute arbitrary web scripts.
No, Internet Explorer itself is not vulnerable, but the XSS vulnerabilities in IBM Cognos Command Center when used with it can be exploited.