CVE-2013-0587
Summary
| CVE | CVE-2013-0587 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-08-16 01:55:15 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Portal before 8.0.0.1 CF07 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Portal, (2) Portal 7.0.0.2, (3) Portal 8.0, or (4) PortalWeb2 theme. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Websphere Portal | 5.1.0.0 | All | All | All |
| Application | Ibm | Websphere Portal | 5.1.0.1 | All | All | All |
| Application | Ibm | Websphere Portal | 5.1.0.2 | All | All | All |
| Application | Ibm | Websphere Portal | 5.1.0.3 | All | All | All |
| Application | Ibm | Websphere Portal | 5.1.0.4 | All | All | All |
| Application | Ibm | Websphere Portal | 5.1.0.5 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.0.0 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.0.1 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.0.2 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.0.3 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.0.4 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.0 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.1 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.2 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.3 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.4 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.5 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.5 | wp6015_008_01 | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.6 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.7 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.0 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.1 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.2 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.3 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.5.0 | All | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.0 | All | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.0 | cf001 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.1 | All | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.1 | cf002 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.1 | cf003 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.1 | cf004 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.1 | cf005 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.1 | cf006 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.1 | cf007 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.1 | cf008 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.1 | cf009 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.1 | cf010 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.1 | cf019 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.2 | All | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.2 | cf011 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.2 | cf012 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.2 | cf013 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.2 | cf014 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.2 | cf015 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.2 | cf016 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.2 | cf017 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.2 | cf018 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.2 | cf019 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.2 | cf020 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.2 | cf021 | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.2 | cf022 | All | All |
| Application | Ibm | Websphere Portal | 8.0 | All | All | All |
| Application | Ibm | Websphere Portal | 8.0.0.0 | All | All | All |
| Application | Ibm | Websphere Portal | 8.0.0.0 | cf01 | All | All |
| Application | Ibm | Websphere Portal | 8.0.0.0 | cf02 | All | All |
| Application | Ibm | Websphere Portal | 8.0.0.0 | cf03 | All | All |
| Application | Ibm | Websphere Portal | 8.0.0.0 | cf04 | All | All |
| Application | Ibm | Websphere Portal | 8.0.0.0 | cf05 | All | All |
| Application | Ibm | Websphere Portal | 8.0.0.1 | All | All | All |
| Application | Ibm | Websphere Portal | 8.0.0.1 | cf04 | All | All |
| Application | Ibm | Websphere Portal | 8.0.0.1 | cf05 | All | All |
| Application | Ibm | Websphere Portal | All | cf06 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Security Bulletin: Cross Site Scripting vulnerabilities in themes of WebSphere Portal (CVE-2013-0587) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.