what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

IBM iNotes Cross Site Scripting

IBM iNotes Cross Site Scripting
Posted Aug 27, 2013
Authored by Alexander Klink

IBM Lotus iNotes suffered from four cross site scripting vulnerabilities.

tags | advisory, vulnerability, xss
advisories | CVE-2013-0590, CVE-2013-0591, CVE-2013-0595
SHA-256 | 618ce3eda1131f575c8580bda8bf0d3b521173ae62782e832850453ccb773385

IBM iNotes Cross Site Scripting

Change Mirror Download
Abstract

IBM® Lotus iNotes® 8.5.x contains four cross-site scripting vulnerabilities. The fixes for these issues are available in IBM® Lotus Domino® release 8.5.3 Fixpack 5.
Content

IBM iNotes has four cross-site scripting vulnerabilities. Two of the vulnerabilities share the same CVE ID (CVE-2013-0595). These vulnerabilities could allow a remote unauthenticated attacker to expose user personal data.
VULNERABILITY DETAILS: IBM iNotes Cross-site Scripting vulnerabilities

CVE ID: CVE-2013-0590, CVE-2013-0591, CVE-2013-0595

DESCRIPTION: A remote unauthenticated attacker could exploit a security vulnerability in IBM iNotes to expose user personal data.

CVSS:

CVE ID: CVE-2013-0590
CVSS Base Score: 3.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/83814 for the current score.
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/AU:S/C:N/I:P/A:N)

Access Vector: Network Access Complexity: Medium
Authentication: Single Confidentiality Impact: None
Integrity Impact: Partial Availability Impact: None


CVE ID: CVE-2013-0591
CVSS Base Score: 3.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/83381 for the current score.
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/AU:S/C:N/I:P/A:N)

Access Vector: Network Access Complexity: Medium
Authentication: Single Confidentiality Impact: None
Integrity Impact: Partial Availability Impact: None


CVE ID: CVE-2013-0595
CVSS Base Score: 4.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/83431 for the current score.
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/AU:N/C:N/I:P/A:N)

Access Vector: Network Access Complexity: Medium
Authentication: No Confidentiality Impact: None
Integrity Impact: Partial Availability Impact: None

AFFECTED PLATFORMS:

IBM iNotes 8.5.x

REMEDIATION:

Fix:

All three of these issues are being tracked through SPR #PTHN95XNR3. The fix is available in IBM Domino release 8.5.3 Fix Pack 5, which can be accessed here:

http://www-01.ibm.com/support/docview.wss?uid=swg24032242

Workaround:

None

Mitigation(s):

None



REFERENCES:

CVE-2013-0590
CVE-2013-0591
CVE-2013-0595
Complete CVSS Guide
On-line Calculator V2
X-Force Vulnerability Database (http://xforce.iss.net/xforce/xfdb/83814,http://xforce.iss.net/xforce/xfdb/83381 and http://xforce.iss.net/xforce/xfdb/83431)



RELATED INFORMATION:

IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog

ACKNOWLEDGEMENT:
These vulnerabilities were reported to IBM by Alexander Klink of n.runs AG.


Login or Register to add favorites

File Archive:

October 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    10 Files
  • 2
    Oct 2nd
    0 Files
  • 3
    Oct 3rd
    12 Files
  • 4
    Oct 4th
    15 Files
  • 5
    Oct 5th
    18 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    0 Files
  • 8
    Oct 8th
    0 Files
  • 9
    Oct 9th
    0 Files
  • 10
    Oct 10th
    0 Files
  • 11
    Oct 11th
    0 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    0 Files
  • 15
    Oct 15th
    0 Files
  • 16
    Oct 16th
    0 Files
  • 17
    Oct 17th
    0 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By
Rokasec
close