Vulnerability Name: CVE-2013-0474 (CCN-81338) Assigned: 2012-12-16 Published: 2013-03-25 Updated: 2017-08-29 Summary: The Manual Explore browser plug-in in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to discover test Platform Authentication credentials via a crafted web site. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N )3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N )3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-200 Vulnerability Consequences: Cross-Site Scripting References: Source: MITRE Type: CNACVE-2013-0474 Source: CCN Type: SA52765IBM Rational Policy Tester Multiple Vulnerabilities Source: CONFIRM Type: Vendor Advisoryhttp://www-01.ibm.com/support/docview.wss?uid=swg21626264 Source: CCN Type: IBM Security Bulletin 1631304Multiple vulnerabilities in IBM Rational Policy Tester (CVE-2013-0532, CVE-2013-0512, CVE-2012-4431, CVE-2013-0513, CVE-2008-4033, CVE-2013-0474, CVE-2013-0473, CVE-2012-5081) Source: CONFIRM Type: Vendor Advisoryhttp://www-01.ibm.com/support/docview.wss?uid=swg21631304 Source: CCN Type: IBM Security Bulletin 1632346Cross-Site Request Forgery vulnerability in IBM Security AppScan Standard (CVE-2013-0474) Source: CCN Type: IBM Security Bulletin 1626264Multiple vulnerabilities in IBM Security AppScan Enterprise (CVE-2013-0532, CVE-2013-0510, CVE-2013-0512, CVE-2012-4431, CVE-2013-0513, CVE-2008-4033, CVE-2013-0474, CVE-2013-0511, CVE-2013-0473, CVE-2012-5081) Source: CCN Type: BID-58688Multiple IBM products CVE-2013-0474 Information Disclosure Vulnerability Source: XF Type: UNKNOWNappscan-manual-explore-csrf(81338) Source: XF Type: UNKNOWNappscan-manual-explore-csrf(81338) Vulnerable Configuration: Configuration 1 :cpe:/a:ibm:security_appscan:5.6.0.0:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.0.0:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.0.1:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.0.2:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.1.0:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.1.1:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.11:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.5.0.0:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.5.0.1:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.6.0.0:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.6.0.1:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.6.0.2:-:enterprise:*:*:*:*:* Configuration 2 :cpe:/a:ibm:rational_policy_tester:5.6.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.0.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.0.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.0.1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.0.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.5.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.5.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.5.0.3:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:ibm:rational_policy_tester:8.0.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_appscan:5.2:*:enterprise:*:*:*:*:* OR cpe:/a:ibm:rational_appscan:8.0.0:*:enterprise:*:*:*:*:* OR cpe:/a:ibm:rational_appscan:8.5.0:*:enterprise:*:*:*:*:* Denotes that component is vulnerable BACK
ibm security appscan 5.6.0.0 -
ibm security appscan 8.0.0.0 -
ibm security appscan 8.0.0.1 -
ibm security appscan 8.0.0.2 -
ibm security appscan 8.0.1.0 -
ibm security appscan 8.0.1.1 -
ibm security appscan 8.0.11 -
ibm security appscan 8.5.0.0 -
ibm security appscan 8.5.0.1 -
ibm security appscan 8.6.0.0 -
ibm security appscan 8.6.0.1 -
ibm security appscan 8.6.0.2 -
ibm rational policy tester 5.6.0.0
ibm rational policy tester 8.0.0.0
ibm rational policy tester 8.0.0.1
ibm rational policy tester 8.0.0.2
ibm rational policy tester 8.0.1.0
ibm rational policy tester 8.0.1.1
ibm rational policy tester 8.5.0.0
ibm rational policy tester 8.5.0.1
ibm rational policy tester 8.5.0.2
ibm rational policy tester 8.5.0.3
ibm rational policy tester 8.0.0.0
ibm rational appscan 5.2
ibm rational appscan 8.0.0
ibm rational appscan 8.5.0