Security Bulletin
Summary
Cross-site scripting in Oauth
Vulnerability Details
CVE ID: CVE-2013-6738
DESCRIPTION:
OAuth /authorize endpoint will return an invalid query param in the response. This allows a script to be injected in the response.
CVSS:
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/89854 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Any customer using version 1.1 should call IBM Support for guidance.
Affected Products and Versions
IBM SmartCloud Analytics LogAnalysis v1.1 and v1.2
Remediation/Fixes
IBM SmartCloud Analytics LogAnalysis 1.2.0.0-CSI-SCALA-IF0003 APAR ID - IV57425
Workarounds and Mitigations
None
Get Notified about Future Security Bulletins
References
Change History
02 April 2014: Original Version Published
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Was this topic helpful?
Document Information
Modified date:
17 June 2018
UID
swg21669137