Description
Cross-site scripting (XSS) vulnerability in the echo functionality on IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0, 4.0.1, 4.0.2, and 5.0.0 allows remote attackers to inject arbitrary web script or HTML via a SOAP message, as demonstrated by the XML Firewall, Multi Protocol Gateway (MPGW), Web Service Proxy, and Web Token services.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-0510 | Cross-site scripting (XSS) vulnerability in the echo functionality on IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0, 4.0.1, 4.0.2, and 5.0.0 allows remote attackers to inject arbitrary web script or HTML via a SOAP message, as demonstrated by the XML Firewall, Multi Protocol Gateway (MPGW), Web Service Proxy, and Web Token services. |
References
History
No history.
Subscriptions
Ibm
Subscribe
Websphere Datapower B2b Appliance Xb62
Subscribe
Websphere Datapower B2b Appliance Xb62 Firmware
Subscribe
Websphere Datapower Integration Appliance Xi50
Subscribe
Websphere Datapower Integration Appliance Xi50 Firmware
Subscribe
Websphere Datapower Integration Appliance Xi52
Subscribe
Websphere Datapower Integration Appliance Xi52 Firmware
Subscribe
Websphere Datapower Integration Appliance Xi52 Virtual Edition
Subscribe
Websphere Datapower Integration Appliance Xi52 Virtual Edition Firmware
Subscribe
Websphere Datapower Service Gateway Xg45
Subscribe
Websphere Datapower Service Gateway Xg45 Firmware
Subscribe
Websphere Datapower Service Gateway Xg45 Virtual Edition
Subscribe
Websphere Datapower Service Gateway Xg45 Virtual Edition Firmware
Subscribe
Websphere Datapower Xc10 Appliance
Subscribe
Websphere Datapower Xc10 Appliance Firmware
Subscribe
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-08-06T14:25:10.355Z
Reserved: 2012-12-16T00:00:00.000Z
Link: CVE-2013-0499
No data.
Status : Modified
Published: 2013-05-28T16:55:01.133
Modified: 2026-04-29T01:13:23.040
Link: CVE-2013-0499
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD