First published: Thu Jan 16 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server with Web Server Plug-ins | =6.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.3 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.4 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.5 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.6 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.7 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.8 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.9 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.10 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.11 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.12 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.13 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.14 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.15 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.16 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.17 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.18 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.19 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.21 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.22 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.23 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.24 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.25 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.27 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.29 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.3 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.4 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.5 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.6 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.7 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.0.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.0.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.0.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.5.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6725 has a medium severity rating due to its potential for cross-site scripting attacks.
Fix CVE-2013-6725 by updating IBM WebSphere Application Server to the latest version that addresses this vulnerability.
CVE-2013-6725 affects IBM WebSphere Application Server versions 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2.
Yes, CVE-2013-6725 can be exploited remotely by an authenticated administrator through a crafted URL.
CVE-2013-6725 is a cross-site scripting (XSS) vulnerability.