CVE-2013-0502

IBM InfoSphere Information Server <9.1 - XSS

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server 8.1, 8.5 through FP3, 8.7 through FP2, and 9.1 allows remote attackers to inject arbitrary web script or HTML via a malformed URL.

References (3)

Core 3
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1JR45274
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/82233
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21632556

Scores

EPSS 0.0115
EPSS Percentile 63.5%

Details

CWE
CWE-79
Status published
Products (9)
ibm/infosphere_information_server 8.1
ibm/infosphere_information_server 8.5
ibm/infosphere_information_server 8.5.0.1
ibm/infosphere_information_server 8.5.0.2
ibm/infosphere_information_server 8.5.0.3
ibm/infosphere_information_server 8.7
ibm/infosphere_information_server 8.7.0.1
ibm/infosphere_information_server 8.7.0.2
ibm/infosphere_information_server 9.1
Published Apr 01, 2013
Tracked Since Feb 18, 2026