CVE-2013-3979
Summary
| CVE | CVE-2013-3979 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-07-25 11:59:07 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Web\Content\Help\ in the Web Client in IBM Cognos Command Center (aka Star Command Center or Star Analytics) before 10.1, when Internet Explorer is used, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Star Command Center | 1.6.1 | All | All | All |
| Application | Ibm | Star Command Center | 3.0.0 | All | All | All |
| Application | Ibm | Star Command Center | 3.0.1 | All | All | All |
| Application | Ibm | Star Command Center | 3.0.2 | All | All | All |
| Application | Ibm | Star Command Center | 3.0.3 | All | All | All |
| Application | Ibm | Star Command Center | 3.0.4 | All | All | All |
| Application | Ibm | Star Command Center | 3.0.5 | All | All | All |
| Application | Ibm | Star Command Center | 3.0.6 | All | All | All |
| Application | Ibm | Star Command Center | 3.0.7 | All | All | All |
| Application | Microsoft | Internet Explorer | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Security Advisory SA54286 - IBM Cognos Command Center Unspecified Cross-Site Scripting Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| IBM Cognos Command Center Unspecified Cross Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM Cognos Star Command Center Input Validation Flaw Permits Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.