CVE-2013-0499
28.05.2013, 16:55
Cross-site scripting (XSS) vulnerability in the echo functionality on IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0, 4.0.1, 4.0.2, and 5.0.0 allows remote attackers to inject arbitrary web script or HTML via a SOAP message, as demonstrated by the XML Firewall, Multi Protocol Gateway (MPGW), Web Service Proxy, and Web Token services.
Vendor | Product | Version |
---|---|---|
ibm | websphere_datapower_xc10_appliance_firmware | 3.8.2 |
ibm | websphere_datapower_xc10_appliance_firmware | 4.0 |
ibm | websphere_datapower_xc10_appliance_firmware | 4.0.1 |
ibm | websphere_datapower_xc10_appliance_firmware | 4.0.2 |
ibm | websphere_datapower_xc10_appliance_firmware | 5.0.0 |
ibm | websphere_datapower_xc10_appliance | - |
ibm | websphere_datapower_service_gateway_xg45_virtual_edition_firmware | 3.8.2 |
ibm | websphere_datapower_service_gateway_xg45_virtual_edition_firmware | 4.0 |
ibm | websphere_datapower_service_gateway_xg45_virtual_edition_firmware | 4.0.1 |
ibm | websphere_datapower_service_gateway_xg45_virtual_edition_firmware | 4.0.2 |
ibm | websphere_datapower_service_gateway_xg45_virtual_edition_firmware | 5.0.0 |
ibm | websphere_datapower_service_gateway_xg45_virtual_edition | - |
ibm | websphere_datapower_service_gateway_xg45_firmware | 3.8.2 |
ibm | websphere_datapower_service_gateway_xg45_firmware | 4.0 |
ibm | websphere_datapower_service_gateway_xg45_firmware | 4.0.1 |
ibm | websphere_datapower_service_gateway_xg45_firmware | 4.0.2 |
ibm | websphere_datapower_service_gateway_xg45_firmware | 5.0.0 |
ibm | websphere_datapower_service_gateway_xg45 | - |
ibm | websphere_datapower_integration_appliance_xi52_virtual_edition_firmware | 3.8.2 |
ibm | websphere_datapower_integration_appliance_xi52_virtual_edition_firmware | 4.0 |
ibm | websphere_datapower_integration_appliance_xi52_virtual_edition_firmware | 4.0.1 |
ibm | websphere_datapower_integration_appliance_xi52_virtual_edition_firmware | 4.0.2 |
ibm | websphere_datapower_integration_appliance_xi52_virtual_edition_firmware | 5.0.0 |
ibm | websphere_datapower_integration_appliance_xi52_virtual_edition | - |
ibm | websphere_datapower_integration_appliance_xi52_firmware | 3.8.2 |
ibm | websphere_datapower_integration_appliance_xi52_firmware | 4.0 |
ibm | websphere_datapower_integration_appliance_xi52_firmware | 4.0.1 |
ibm | websphere_datapower_integration_appliance_xi52_firmware | 4.0.2 |
ibm | websphere_datapower_integration_appliance_xi52_firmware | 5.0.0 |
ibm | websphere_datapower_integration_appliance_xi52 | - |
ibm | websphere_datapower_integration_appliance_xi50_firmware | 3.8.2 |
ibm | websphere_datapower_integration_appliance_xi50_firmware | 4.0 |
ibm | websphere_datapower_integration_appliance_xi50_firmware | 4.0.1 |
ibm | websphere_datapower_integration_appliance_xi50_firmware | 4.0.2 |
ibm | websphere_datapower_integration_appliance_xi50_firmware | 5.0.0 |
ibm | websphere_datapower_integration_appliance_xi50 | - |
ibm | websphere_datapower_b2b_appliance_xb62_firmware | 3.8.2 |
ibm | websphere_datapower_b2b_appliance_xb62_firmware | 4.0 |
ibm | websphere_datapower_b2b_appliance_xb62_firmware | 4.0.1 |
ibm | websphere_datapower_b2b_appliance_xb62_firmware | 4.0.2 |
ibm | websphere_datapower_b2b_appliance_xb62_firmware | 5.0.0 |
ibm | websphere_datapower_b2b_appliance_xb62 | - |
𝑥
= Vulnerable software versions
References