Cross-Site Scripting Vulnerability in IBM Storwize V7000 Unified
CVE-2013-5376

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
17 October 2013

Summary

The XSS vulnerability in IBM Storwize V7000 Unified versions 1.3.x and 1.4.x prior to 1.4.2.0 allows remote authenticated users to execute arbitrary web scripts or HTML on affected systems. This risk is amplified through 'cross frame scripting' attacks, potentially affecting administrative users by allowing unauthorized manipulation of the web interface.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.