First published: Mon Sep 16 2013(Updated: )
Cross-site scripting (XSS) vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote attackers to inject arbitrary web script or HTML via a crafted link.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SPSS Analytical Decision Management | =6.1.0.0 | |
IBM SPSS Analytical Decision Management | =6.2.0.0 | |
IBM SPSS Analytical Decision Management | =7.0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-4047 is considered medium due to its potential for cross-site scripting attacks.
To fix CVE-2013-4047, upgrade to IBM SPSS Analytical Decision Management version 6.1 IF1, 6.2 IF1, or 7.0 FP1 IF6.
CVE-2013-4047 affects IBM SPSS Analytical Decision Management versions 6.1, 6.2, and 7.0 before their respective fixes.
Yes, CVE-2013-4047 can be exploited remotely by attackers injecting malicious web scripts via crafted links.
CVE-2013-4047 is a cross-site scripting (XSS) vulnerability, allowing for the injection of arbitrary HTML or web scripts.