what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

IBM iNotes Cross Site Scripting

IBM iNotes Cross Site Scripting
Posted Aug 27, 2013
Authored by Alexander Klink

IBM Lotus iNotes suffered from four cross site scripting vulnerabilities.

tags | advisory, vulnerability, xss
advisories | CVE-2013-0590, CVE-2013-0591, CVE-2013-0595
SHA-256 | 618ce3eda1131f575c8580bda8bf0d3b521173ae62782e832850453ccb773385

IBM iNotes Cross Site Scripting

Change Mirror Download
Abstract

IBM® Lotus iNotes® 8.5.x contains four cross-site scripting vulnerabilities. The fixes for these issues are available in IBM® Lotus Domino® release 8.5.3 Fixpack 5.
Content

IBM iNotes has four cross-site scripting vulnerabilities. Two of the vulnerabilities share the same CVE ID (CVE-2013-0595). These vulnerabilities could allow a remote unauthenticated attacker to expose user personal data.
VULNERABILITY DETAILS: IBM iNotes Cross-site Scripting vulnerabilities

CVE ID: CVE-2013-0590, CVE-2013-0591, CVE-2013-0595

DESCRIPTION: A remote unauthenticated attacker could exploit a security vulnerability in IBM iNotes to expose user personal data.

CVSS:

CVE ID: CVE-2013-0590
CVSS Base Score: 3.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/83814 for the current score.
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/AU:S/C:N/I:P/A:N)

Access Vector: Network Access Complexity: Medium
Authentication: Single Confidentiality Impact: None
Integrity Impact: Partial Availability Impact: None


CVE ID: CVE-2013-0591
CVSS Base Score: 3.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/83381 for the current score.
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/AU:S/C:N/I:P/A:N)

Access Vector: Network Access Complexity: Medium
Authentication: Single Confidentiality Impact: None
Integrity Impact: Partial Availability Impact: None


CVE ID: CVE-2013-0595
CVSS Base Score: 4.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/83431 for the current score.
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/AU:N/C:N/I:P/A:N)

Access Vector: Network Access Complexity: Medium
Authentication: No Confidentiality Impact: None
Integrity Impact: Partial Availability Impact: None

AFFECTED PLATFORMS:

IBM iNotes 8.5.x

REMEDIATION:

Fix:

All three of these issues are being tracked through SPR #PTHN95XNR3. The fix is available in IBM Domino release 8.5.3 Fix Pack 5, which can be accessed here:

http://www-01.ibm.com/support/docview.wss?uid=swg24032242

Workaround:

None

Mitigation(s):

None



REFERENCES:

CVE-2013-0590
CVE-2013-0591
CVE-2013-0595
Complete CVSS Guide
On-line Calculator V2
X-Force Vulnerability Database (http://xforce.iss.net/xforce/xfdb/83814,http://xforce.iss.net/xforce/xfdb/83381 and http://xforce.iss.net/xforce/xfdb/83431)



RELATED INFORMATION:

IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog

ACKNOWLEDGEMENT:
These vulnerabilities were reported to IBM by Alexander Klink of n.runs AG.


Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    0 Files
  • 9
    Sep 9th
    0 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close