First published: Wed Mar 05 2014(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-6299, CVE-2013-6300, CVE-2013-6301, and CVE-2013-6333.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Algo One | =4.7.0 | |
IBM Algo One | =4.7.1 | |
IBM Algo One | =4.8.0 | |
IBM Algo One | =4.9.0 | |
IBM Algo One | =4.9.1 | |
IBM Algo One | =5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6320 is considered a medium severity vulnerability due to the potential for Cross-site scripting (XSS) attacks.
To fix CVE-2013-6320, it is recommended to update IBM Algo One to the latest version that has addressed this vulnerability.
CVE-2013-6320 affects IBM Algo One versions 4.7.0 to 5.0.0, including MetaData Management Tools and ACSWeb.
CVE-2013-6320 requires remote authenticated users to exploit the XSS vulnerability.
CVE-2013-6320 enables remote authenticated users to inject arbitrary web scripts or HTML into the application.