First published: Thu May 01 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, and WebSphere Virtual Enterprise 7.x before 7.0.0.5, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Virtual Enterprise | =7.0 | |
IBM WebSphere Virtual Enterprise | =7.0.0.1 | |
IBM WebSphere Virtual Enterprise | =7.0.0.2 | |
IBM WebSphere Virtual Enterprise | =7.0.0.3 | |
IBM WebSphere Virtual Enterprise | =7.0.0.4 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.3 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.4 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.5 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.6 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.7 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.8 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.9 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.10 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.11 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.12 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.13 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.14 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.15 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.16 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.17 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.18 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.19 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.21 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.22 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.23 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.24 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.25 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.27 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.29 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.31 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.0.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.0.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.0.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.5.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.5.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.3 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.4 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.5 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.6 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.7 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6323 is considered a moderate-severity cross-site scripting (XSS) vulnerability affecting IBM WebSphere Application Server and WebSphere Virtual Enterprise.
To fix CVE-2013-6323, upgrade to IBM WebSphere Application Server versions 7.0.0.33, 8.0.0.9, or 8.5.5.2 or later, and apply the relevant patches.
CVE-2013-6323 affects IBM WebSphere Application Server versions 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2.
Yes, CVE-2013-6323 allows remote authenticated users to exploit the vulnerability by injecting arbitrary web scripts.
CVE-2013-6323 impacts the IBM WebSphere Application Server and IBM WebSphere Virtual Enterprise software.