{"api_version":"1","generated_at":"2026-07-23T08:31:45+00:00","cve":"CVE-2013-6746","urls":{"html":"https://cve.report/CVE-2013-6746","api":"https://cve.report/api/cve/CVE-2013-6746.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-6746","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-6746"},"summary":{"title":"CVE-2013-6746","description":"Cross-site scripting (XSS) vulnerability in FileNet P8 Platform Documentation Installable Info Center 4.5.1 through 5.2.0 in IBM FileNet Business Process Manager 4.5.1 through 5.1.0, FileNet Content Manager 4.5.1 through 5.2.0, and Case Foundation 5.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","state":"PUBLISHED","assigner":"ibm","published_at":"2014-01-22 05:22:15","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/56500","name":"http://secunia.com/advisories/56500","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA56500 - IBM Multiple Products Filenet P8 Platform Documentation Cross-Site Scripting Vulnerability - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ibm.com/support/docview.wss?uid=swg21662360","name":"http://www.ibm.com/support/docview.wss?uid=swg21662360","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Bulletin: IBM FileNet P8 Platform Documentation Installable Info Center cross-site scripting vulnerability (CVE-2013-6746)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/65045","name":"http://www.securityfocus.com/bid/65045","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Multiple IBM Products CVE-2013-6746 Cross Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/89862","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/89862","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-6746","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-6746","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"6746","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"filenet_case_foundation","cpe6":"5.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"6746","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"filenet_content_manager","cpe6":"4.5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"6746","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"filenet_content_manager","cpe6":"4.5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"6746","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"filenet_content_manager","cpe6":"5.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"6746","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"filenet_content_manager","cpe6":"5.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"6746","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"filenet_content_manager","cpe6":"5.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"6746","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"filenet_p8_business_process_manager","cpe6":"4.5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"6746","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"filenet_p8_business_process_manager","cpe6":"5.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"6746","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"filenet_p8_business_process_manager","cpe6":"5.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2013","cve_id":"6746","cve":"CVE-2013-6746","epss":"0.002560000","percentile":"0.489330000","score_date":"2026-05-03","updated_at":"2026-05-04 00:13:06"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T17:46:23.396Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"65045","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/65045"},{"name":"ibm-filenet-cve20136746-xss(89862)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/89862"},{"name":"56500","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/56500"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.ibm.com/support/docview.wss?uid=swg21662360"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-12-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in FileNet P8 Platform Documentation Installable Info Center 4.5.1 through 5.2.0 in IBM FileNet Business Process Manager 4.5.1 through 5.1.0, FileNet Content Manager 4.5.1 through 5.2.0, and Case Foundation 5.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"name":"65045","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/65045"},{"name":"ibm-filenet-cve20136746-xss(89862)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/89862"},{"name":"56500","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/56500"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.ibm.com/support/docview.wss?uid=swg21662360"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2013-6746","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in FileNet P8 Platform Documentation Installable Info Center 4.5.1 through 5.2.0 in IBM FileNet Business Process Manager 4.5.1 through 5.1.0, FileNet Content Manager 4.5.1 through 5.2.0, and Case Foundation 5.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"65045","refsource":"BID","url":"http://www.securityfocus.com/bid/65045"},{"name":"ibm-filenet-cve20136746-xss(89862)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/89862"},{"name":"56500","refsource":"SECUNIA","url":"http://secunia.com/advisories/56500"},{"name":"http://www.ibm.com/support/docview.wss?uid=swg21662360","refsource":"CONFIRM","url":"http://www.ibm.com/support/docview.wss?uid=swg21662360"}]}}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2013-6746","datePublished":"2014-01-22T02:00:00.000Z","dateReserved":"2013-11-08T00:00:00.000Z","dateUpdated":"2024-08-06T17:46:23.396Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-01-22 05:22:15","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:filenet_case_foundation:5.2.0:*:*:*:*:*:*:*","matchCriteriaId":"4A7073F3-7611-4267-B0E9-630B333EE16B"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:filenet_content_manager:4.5.0:*:*:*:*:*:*:*","matchCriteriaId":"2F852D8F-AFB9-44C7-878D-8A9D6279ACE6"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:filenet_content_manager:4.5.1:*:*:*:*:*:*:*","matchCriteriaId":"05F86DAF-332E-4CF1-9D7D-99A8AD10B155"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:filenet_content_manager:5.0.0:*:*:*:*:*:*:*","matchCriteriaId":"4733131C-1749-48A2-8B6A-60CF990476EC"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:filenet_content_manager:5.1.0:*:*:*:*:*:*:*","matchCriteriaId":"C70F33AB-DC33-464D-8D30-066F3FF00E82"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:filenet_content_manager:5.2.0:*:*:*:*:*:*:*","matchCriteriaId":"CB402686-BDC8-4A38-A395-3759215FD963"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:filenet_p8_business_process_manager:4.5.1:*:*:*:*:*:*:*","matchCriteriaId":"B6BF4D57-4E31-457A-812E-C2BBC43B9785"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:filenet_p8_business_process_manager:5.0.0:*:*:*:*:*:*:*","matchCriteriaId":"AAF053C6-A526-4C65-AC19-8989B98504FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:filenet_p8_business_process_manager:5.1.0:*:*:*:*:*:*:*","matchCriteriaId":"C876167F-0398-4E9E-8186-30523966BDB1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"6746","Ordinal":"1","Title":"CVE-2013-6746","CVE":"CVE-2013-6746","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"6746","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in FileNet P8 Platform Documentation Installable Info Center 4.5.1 through 5.2.0 in IBM FileNet Business Process Manager 4.5.1 through 5.1.0, FileNet Content Manager 4.5.1 through 5.2.0, and Case Foundation 5.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","Type":"Description","Title":"CVE-2013-6746"},{"CveYear":"2013","CveId":"6746","Ordinal":"2","NoteData":"2014-01-21","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"6746","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}