IBM InfoSphere BigInsights CVE-2013-3995 Unspecified Cross Site Scripting Vulnerability
BID:61845
Info
IBM InfoSphere BigInsights CVE-2013-3995 Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 61845 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3995 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2013 12:00AM |
| Updated: | Aug 02 2013 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM InfoSphere BigInsights 2.1 IBM InfoSphere BigInsights 2.0 IBM InfoSphere BigInsights 1.4 IBM InfoSphere BigInsights 1.3 IBM InfoSphere BigInsights 1.2 IBM InfoSphere BigInsights 1.1 |
| Not Vulnerable: | |
Discussion
IBM InfoSphere BigInsights CVE-2013-3995 Unspecified Cross Site Scripting Vulnerability
IBM InfoSphere BigInsights is prone to an unspecified cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
IBM InfoSphere BigInsights versions 1.1 through 2.1 are vulnerable.
Note: This issue was previously discussed in BID 61604 (IBM InfoSphere BigInsights Multiple Security Vulnerabilities), but has been given its own record to better document it.
IBM InfoSphere BigInsights is prone to an unspecified cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
IBM InfoSphere BigInsights versions 1.1 through 2.1 are vulnerable.
Note: This issue was previously discussed in BID 61604 (IBM InfoSphere BigInsights Multiple Security Vulnerabilities), but has been given its own record to better document it.
Solution / Fix
IBM InfoSphere BigInsights CVE-2013-3995 Unspecified Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM InfoSphere BigInsights CVE-2013-3995 Unspecified Cross Site Scripting Vulnerability
References:
References: