CVE-2013-4036

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 FP13, and IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP7 and 11.0 before FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:N/I:P/A:N
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
VendorProductVersion
ibminfosphere_master_data_management_server_for_product_information_management
9.0
ibminfosphere_master_data_management_server_for_product_information_management
9.1
ibminfosphere_master_data_management_collaboration_server
10.0
ibminfosphere_master_data_management_collaboration_server
10.1
ibminfosphere_master_data_management_collaboration_server
11.0
𝑥
= Vulnerable software versions