Multiple IBM Products CVE-2013-6746 Cross Site Scripting Vulnerability
BID:65045
Info
Multiple IBM Products CVE-2013-6746 Cross Site Scripting Vulnerability
| Bugtraq ID: | 65045 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-6746 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2014 12:00AM |
| Updated: | Jan 20 2014 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM FileNet Content Manager 5.2.0 IBM FileNet Content Manager 5.1 IBM FileNet Content Manager 5.0 IBM FileNet Content Manager 4.5.1 IBM FileNet Business Process Manager 5.1 IBM FileNet Business Process Manager 5.0 IBM FileNet Business Process Manager 4.5.1 IBM Case Foundation 5.2 |
| Not Vulnerable: | |
Discussion
Multiple IBM Products CVE-2013-6746 Cross Site Scripting Vulnerability
Multiple IBM Products are prone to a cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
The following product versions are affected:
IBM Case Foundation 5.2.0
IBM FileNet Business Process Manager 4.5.1
IBM FileNet Business Process Manager 5.0.0
IBM FileNet Business Process Manager 5.1.0
IBM FileNet Content Manager 4.5.1
IBM FileNet Content Manager 5.0.0
IBM FileNet Content Manager 5.1.0
IBM FileNet Content Manager 5.2.0
Multiple IBM Products are prone to a cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
The following product versions are affected:
IBM Case Foundation 5.2.0
IBM FileNet Business Process Manager 4.5.1
IBM FileNet Business Process Manager 5.0.0
IBM FileNet Business Process Manager 5.1.0
IBM FileNet Content Manager 4.5.1
IBM FileNet Content Manager 5.0.0
IBM FileNet Content Manager 5.1.0
IBM FileNet Content Manager 5.2.0
Exploit / POC
Multiple IBM Products CVE-2013-6746 Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim into following a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting victim into following a malicious URI.
References
Multiple IBM Products CVE-2013-6746 Cross Site Scripting Vulnerability
References:
References:
- FileNet Business Process Manager Homepage (IBM)
- FileNet Content Manager Homepage (IBM)
- FileNet P8 Platform V5.0 Documentation Updates (IBM)
- FileNet P8 Platform V5.1 Documentation Updates (IBM)
- IBM Homepage (IBM)
- FileNet P8 Platform Version 4.5.1 security patches for installable information c (IBM)
- FileNet P8 Platform Version 5.2 documentation updates for installable informatio (IBM)
- IBM FileNet P8 Platform Documentation Installable Info Center cross-site scripti (IBM)