Vulnerability Name: | CVE-2013-5406 (CCN-87355) | ||||||||
Assigned: | 2013-12-05 | ||||||||
Published: | 2013-12-05 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, leading to improper interaction with the Windows MHTML protocol handler. | ||||||||
CVSS v3 Severity: | 2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-5406 Source: CCN Type: SA56198 IBM Sterling B2B Integrator / IBM Sterling File Gateway Multiple Vulnerabilities Source: AIXAPAR Type: UNKNOWN IC96055 Source: CCN Type: IBM Security Bulletin 1657539 Security Bulletin: Vulnerabilities found in IBM Sterling B2B Integrator and IBM Sterling File Gateway (CVE-2013-4002, CVE-2013-5409, CVE-2013-5405, CVE-2013-5406, CVE-2013-5407, CVE-2013-5411, CVE-2013-5413) Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21657539 Source: BID Type: UNKNOWN 64446 Source: CCN Type: BID-64446 IBM Sterling B2B Integrator and Sterling File Gateway Cross Site Scripting Vulnerability Source: XF Type: UNKNOWN ibm-sterling-cve20135406-xss(87355) Source: XF Type: UNKNOWN ibm-sterling-cve20135406-mhtml-xss(87355) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |