CVE-2013-4004: XSS
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.7 and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4004?
CVE-2013-4004 is classified as a medium severity cross-site scripting (XSS) vulnerability that can allow attackers to inject arbitrary web scripts or HTML.
How do I fix CVE-2013-4004?
To mitigate CVE-2013-4004, upgrade your IBM WebSphere Application Server to version 8.0.0.7 or 8.5.5.1 or later.
Who is affected by CVE-2013-4004?
CVE-2013-4004 affects IBM WebSphere Application Server versions 8.0.0.0 through 8.0.0.6 and versions 8.5.0.0 through 8.5.0.2.
Can CVE-2013-4004 be exploited remotely?
Yes, CVE-2013-4004 can be exploited by remote authenticated users who can inject malicious scripts via unspecified vectors.
What is cross-site scripting related to CVE-2013-4004?
Cross-site scripting in the context of CVE-2013-4004 refers to the ability of an attacker to inject harmful scripts into the administrative console of WebSphere Application Server.