CVE-2013-6746
Summary
| CVE | CVE-2013-6746 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-01-22 05:22:15 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site scripting (XSS) vulnerability in FileNet P8 Platform Documentation Installable Info Center 4.5.1 through 5.2.0 in IBM FileNet Business Process Manager 4.5.1 through 5.1.0, FileNet Content Manager 4.5.1 through 5.2.0, and Case Foundation 5.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS: 0.002560000 probability, percentile 0.489330000 (date 2026-05-03)
Problem Types: CWE-79 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Filenet Case Foundation | 5.2.0 | All | All | All |
| Application | Ibm | Filenet Content Manager | 4.5.0 | All | All | All |
| Application | Ibm | Filenet Content Manager | 4.5.1 | All | All | All |
| Application | Ibm | Filenet Content Manager | 5.0.0 | All | All | All |
| Application | Ibm | Filenet Content Manager | 5.1.0 | All | All | All |
| Application | Ibm | Filenet Content Manager | 5.2.0 | All | All | All |
| Application | Ibm | Filenet P8 Business Process Manager | 4.5.1 | All | All | All |
| Application | Ibm | Filenet P8 Business Process Manager | 5.0.0 | All | All | All |
| Application | Ibm | Filenet P8 Business Process Manager | 5.1.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory SA56500 - IBM Multiple Products Filenet P8 Platform Documentation Cross-Site Scripting Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Bulletin: IBM FileNet P8 Platform Documentation Installable Info Center cross-site scripting vulnerability (CVE-2013-6746) | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Vendor Advisory |
| Multiple IBM Products CVE-2013-6746 Cross Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.