First published: Tue Dec 17 2013(Updated: )
Cross-site scripting (XSS) vulnerability in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.x through 8.0.0.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving widgets.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Service Registry and Repository | =7.5 | |
IBM WebSphere Service Registry and Repository | =7.5.0.1 | |
IBM WebSphere Service Registry and Repository | =7.5.0.2 | |
IBM WebSphere Service Registry and Repository | =7.5.0.3 | |
IBM WebSphere Service Registry and Repository | =8.0.0 | |
IBM WebSphere Service Registry and Repository | =8.0.0.1 | |
IBM WebSphere Service Registry and Repository | =8.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6721 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2013-6721, upgrade IBM WebSphere Service Registry and Repository to version 7.5.0.4 or 8.0.0.3 or later.
CVE-2013-6721 can be exploited to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML.
CVE-2013-6721 affects IBM WebSphere Service Registry and Repository versions 7.5.0.2, 7.5.0.3, and 8.0.0.0 through 8.0.0.2.
Remote authenticated users of vulnerable versions of IBM WebSphere Service Registry and Repository are impacted by CVE-2013-6721.