CVE-2013-6733: XSS
Published Dec 17, 2013
·Updated
Cross-site scripting (XSS) vulnerability in the Web Application in the Classic Meeting Server in IBM Sametime 7.5.1.2 through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
11 affected components
IBM Sametime=7.5.1.2
IBM Sametime=8.0.0.0
IBM Sametime=8.0.1.0
IBM Sametime=8.0.1.1
IBM Sametime=8.0.2.0
IBM Sametime=8.0.2.1
IBM Sametime=8.5.0.0
IBM Sametime=8.5.1.0
IBM Sametime=8.5.1.1
IBM Sametime=8.5.2.0
IBM Sametime=8.5.2.1
Event History
Dec 17, 2013
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Data Sourced
via NVD·03:21 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6733?
CVE-2013-6733 is classified as a moderate severity cross-site scripting vulnerability.
2
How do I fix CVE-2013-6733?
To mitigate CVE-2013-6733, upgrade to IBM Sametime versions that are not affected, specifically those released after 8.5.2.1.
3
What versions of HCL Sametime are affected by CVE-2013-6733?
CVE-2013-6733 affects IBM Sametime versions 7.5.1.2 through 8.5.2.1.
4
What type of vulnerability is CVE-2013-6733?
CVE-2013-6733 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
5
Can CVE-2013-6733 be exploited remotely?
Yes, CVE-2013-6733 can be exploited remotely by attackers to inject malicious scripts via unspecified vectors.