Vulnerability Name: | CVE-2013-5407 (CCN-87356) | ||||||||
Assigned: | 2013-12-05 | ||||||||
Published: | 2013-12-05 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information via a crafted web site, related to a "frame injection" issue. | ||||||||
CVSS v3 Severity: | 2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.9 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N/E:H/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-5407 Source: CCN Type: SA56198 IBM Sterling B2B Integrator / IBM Sterling File Gateway Multiple Vulnerabilities Source: AIXAPAR Type: UNKNOWN IC96057 Source: CCN Type: IBM Security Bulletin 1657539 Security Bulletin: Vulnerabilities found in IBM Sterling B2B Integrator and IBM Sterling File Gateway (CVE-2013-4002, CVE-2013-5409, CVE-2013-5405, CVE-2013-5406, CVE-2013-5407, CVE-2013-5411, CVE-2013-5413) Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21657539 Source: CCN Type: BID-64449 IBM Sterling B2B Integrator and Sterling File Gateway Unspecified Frame Injection Vulnerability Source: XF Type: UNKNOWN ibm-sterling-cve20135407-phishing(87356) Source: XF Type: UNKNOWN ibm-sterling-cve20135407-frame-inj(87356) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |