{"api_version":"1","generated_at":"2026-07-23T10:57:50+00:00","cve":"CVE-2013-3034","urls":{"html":"https://cve.report/CVE-2013-3034","api":"https://cve.report/api/cve/CVE-2013-3034.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-3034","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-3034"},"summary":{"title":"CVE-2013-3034","description":"Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the web console.","state":"PUBLISHED","assigner":"ibm","published_at":"2013-08-16 01:55:15","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21646136","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21646136","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Security Bulletin: Multiple security vulnerabilities exist in IBM InfoSphere Information Server  (CVE-2013-0585, CVE-2013-3034, CVE-2013-3040 and CVE-2013-0599)","mime":"text/html","httpstatus":"200","archivestatus":"410"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/84646","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/84646","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/61757","name":"http://www.securityfocus.com/bid/61757","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Malformed Request","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-3034","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-3034","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"3034","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"infosphere_information_server","cpe6":"8.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"3034","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"infosphere_information_server","cpe6":"8.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"3034","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"infosphere_information_server","cpe6":"9.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"3034","vulnerable":"1","versionEndIncluding":"8.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"infosphere_information_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T16:00:10.002Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21646136"},{"name":"61757","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/61757"},{"name":"infosphere-cve20133034-xss(84646)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/84646"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-08-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the web console."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21646136"},{"name":"61757","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/61757"},{"name":"infosphere-cve20133034-xss(84646)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/84646"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2013-3034","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the web console."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21646136","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21646136"},{"name":"61757","refsource":"BID","url":"http://www.securityfocus.com/bid/61757"},{"name":"infosphere-cve20133034-xss(84646)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/84646"}]}}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2013-3034","datePublished":"2013-08-16T01:00:00.000Z","dateReserved":"2013-04-12T00:00:00.000Z","dateUpdated":"2024-08-06T16:00:10.002Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-08-16 01:55:15","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:infosphere_information_server:*:*:*:*:*:*:*:*","versionEndIncluding":"8.5","matchCriteriaId":"0952B898-6071-4709-B6EF-14CD42078181"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:infosphere_information_server:8.1:*:*:*:*:*:*:*","matchCriteriaId":"317FAE67-76E2-4084-9393-8A02D255BAF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:infosphere_information_server:8.7:*:*:*:*:*:*:*","matchCriteriaId":"42A9CF5C-79EC-4BBF-92AF-2AB3DC125684"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:infosphere_information_server:9.1:*:*:*:*:*:*:*","matchCriteriaId":"F3BF0A4B-5DDB-420D-B1F2-8C1ED23F60CF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"3034","Ordinal":"1","Title":"CVE-2013-3034","CVE":"CVE-2013-3034","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"3034","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the web console.","Type":"Description","Title":"CVE-2013-3034"},{"CveYear":"2013","CveId":"3034","Ordinal":"2","NoteData":"2013-08-15","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"3034","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}