CVE-2013-5425: XSS
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Virtual Enterprise 6.1 before 6.1.1.6 and 7.0 before 7.0.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5425?
CVE-2013-5425 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2013-5425?
To fix CVE-2013-5425, upgrade IBM WebSphere Virtual Enterprise to version 6.1.1.6 or 7.0.0.4 or later.
What types of attacks can CVE-2013-5425 enable?
CVE-2013-5425 can enable remote authenticated users to inject malicious web scripts or HTML into the Administration Console.
Which versions of IBM WebSphere Virtual Enterprise are affected by CVE-2013-5425?
CVE-2013-5425 affects IBM WebSphere Virtual Enterprise versions 6.1, 6.1.1 up to 6.1.1.5, and 7.0 up to 7.0.0.3.
Who can exploit CVE-2013-5425?
CVE-2013-5425 can be exploited by remote authenticated users with access to the Administration Console.