First published: Wed Nov 13 2013(Updated: )
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.x before 7.0.0.2 CF25 and 8.x before 8.0.0.1 CF8 allows remote authenticated users to inject arbitrary web script or HTML by leveraging improper tagging functionality.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =7.0.0.0 | |
IBM WebSphere Portal | =7.0.0.1 | |
IBM WebSphere Portal | =7.0.0.2 | |
IBM WebSphere Portal | =8.0.0.0 | |
IBM WebSphere Portal | =8.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5379 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2013-5379, ensure that your IBM WebSphere Portal is updated to version 7.0.0.2 CF25 or 8.0.0.1 CF8 or later.
CVE-2013-5379 affects IBM WebSphere Portal versions 7.0.0.0, 7.0.0.1, 7.0.0.2, 8.0.0.0, and 8.0.0.1.
CVE-2013-5379 is a cross-site scripting (XSS) vulnerability that allows remote authenticated users to inject arbitrary script or HTML.
Yes, CVE-2013-5379 can be exploited remotely by authenticated users through improper tagging functionality.