Cross-Site Scripting in IBM WebSphere DataPower SOA Appliances
CVE-2013-0499
Currently unrated
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 28 May 2013
What is CVE-2013-0499?
A cross-site scripting vulnerability exists in the echo functionality of IBM WebSphere DataPower SOA appliances. This weakness allows attackers to inject arbitrary web scripts or HTML code through crafted SOAP messages. Affected services include XML Firewall, Multi Protocol Gateway (MPGW), Web Service Proxy, and Web Token services, potentially compromising the integrity of the application and the data it processes.