CVE-2013-3995: XSS
Published Aug 5, 2013
·Updated
Cross-site scripting (XSS) vulnerability in IBM InfoSphere BigInsights 1.1 through 2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
9 affected components
IBM Infosphere BigInsights=1.1.0.0
IBM Infosphere BigInsights=1.1.0.1
IBM Infosphere BigInsights=1.1.0.2
IBM Infosphere BigInsights=1.2.0.0
IBM Infosphere BigInsights=1.3.0.0
IBM Infosphere BigInsights=1.3.0.1
IBM Infosphere BigInsights=1.4.0.0
IBM Infosphere BigInsights=2.0.0.0
IBM Infosphere BigInsights=2.1.0.0
Event History
Aug 5, 2013
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3995?
CVE-2013-3995 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2013-3995?
To fix CVE-2013-3995, update IBM InfoSphere BigInsights to a version that has patched this vulnerability.
3
Who is affected by CVE-2013-3995?
CVE-2013-3995 affects remote authenticated users of IBM InfoSphere BigInsights versions 1.1 through 2.1.
4
What types of attacks can CVE-2013-3995 enable?
CVE-2013-3995 can enable attackers to execute arbitrary web scripts or HTML in the context of the user's session.
5
Is there a workaround for CVE-2013-3995?
Currently, there are no known effective workarounds for CVE-2013-3995 aside from applying the necessary updates.