First published: Sat Dec 21 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SPSS Collaboration and Deployment Services | =4.2.1 | |
IBM SPSS Collaboration and Deployment Services | =4.2.1.1 | |
IBM SPSS Collaboration and Deployment Services | =4.2.1.2 | |
IBM SPSS Collaboration and Deployment Services | =4.2.1.3 | |
IBM SPSS Collaboration and Deployment Services | =5.0.0 | |
IBM SPSS Collaboration and Deployment Services | =5.0.0.1 | |
IBM SPSS Collaboration and Deployment Services | =5.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4045 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2013-4045, upgrade to IBM SPSS Collaboration and Deployment Services version 4.2.1.3 or 5.0 FP3 and later.
CVE-2013-4045 affects users of IBM SPSS Collaboration and Deployment Services versions 4.2.1 through 4.2.1.2 and all versions of 5.0 prior to FP3.
CVE-2013-4045 enables remote attackers to inject arbitrary web script or HTML into web pages viewed by users.
The potential impacts of CVE-2013-4045 include session hijacking, redirection to malicious sites, and the execution of unauthorized actions on behalf of users.