CVE-2013-4007: XSS
Cross-site scripting (XSS) vulnerability in advsw.php in the Advanced Management Module (AMM) with firmware BBET before BBET64G and BPET before BPET64G for IBM BladeCenter systems allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4007?
CVE-2013-4007 has been classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2013-4007?
To fix CVE-2013-4007, upgrade the Advanced Management Module firmware to version BBET64G or BPET64G or later.
Which IBM BladeCenter systems are affected by CVE-2013-4007?
CVE-2013-4007 affects the Advanced Management Module firmware versions prior to BBET64G and BPET64G.
Can CVE-2013-4007 allow remote attacks?
Yes, CVE-2013-4007 allows remote attackers to inject arbitrary web scripts or HTML.
What is the affected software for CVE-2013-4007?
The affected software for CVE-2013-4007 includes various versions of the IBM Advanced Management Module.