// For flags

CVE-2013-3979

 

Severity Score

3.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Web\Content\Help\ in the Web Client in IBM Cognos Command Center (aka Star Command Center or Star Analytics) before 10.1, when Internet Explorer is used, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Múltiples vúlnerabilidades de secuencias de comandos en sitios cruzados (XSS) en las páginas de ayuda en Web\Content\Help\ en el cliente Web en IBM Cognos Command Center (también conocido como Star Command Center o Star Analytics) anteriores a v10.1, cuando se utiliza Internet Explorer, permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarias mediante vectores no especificados.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-06-07 CVE Reserved
  • 2013-07-24 CVE Published
  • 2024-06-13 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ibm
Search vendor "Ibm"
Star Command Center
Search vendor "Ibm" for product "Star Command Center"
1.6.1
Search vendor "Ibm" for product "Star Command Center" and version "1.6.1"
-
Affected
in Microsoft
Search vendor "Microsoft"
Internet Explorer
Search vendor "Microsoft" for product "Internet Explorer"
--
Safe
Ibm
Search vendor "Ibm"
Star Command Center
Search vendor "Ibm" for product "Star Command Center"
3.0.0
Search vendor "Ibm" for product "Star Command Center" and version "3.0.0"
-
Affected
in Microsoft
Search vendor "Microsoft"
Internet Explorer
Search vendor "Microsoft" for product "Internet Explorer"
--
Safe
Ibm
Search vendor "Ibm"
Star Command Center
Search vendor "Ibm" for product "Star Command Center"
3.0.1
Search vendor "Ibm" for product "Star Command Center" and version "3.0.1"
-
Affected
in Microsoft
Search vendor "Microsoft"
Internet Explorer
Search vendor "Microsoft" for product "Internet Explorer"
--
Safe
Ibm
Search vendor "Ibm"
Star Command Center
Search vendor "Ibm" for product "Star Command Center"
3.0.2
Search vendor "Ibm" for product "Star Command Center" and version "3.0.2"
-
Affected
in Microsoft
Search vendor "Microsoft"
Internet Explorer
Search vendor "Microsoft" for product "Internet Explorer"
--
Safe
Ibm
Search vendor "Ibm"
Star Command Center
Search vendor "Ibm" for product "Star Command Center"
3.0.3
Search vendor "Ibm" for product "Star Command Center" and version "3.0.3"
-
Affected
in Microsoft
Search vendor "Microsoft"
Internet Explorer
Search vendor "Microsoft" for product "Internet Explorer"
--
Safe
Ibm
Search vendor "Ibm"
Star Command Center
Search vendor "Ibm" for product "Star Command Center"
3.0.4
Search vendor "Ibm" for product "Star Command Center" and version "3.0.4"
-
Affected
in Microsoft
Search vendor "Microsoft"
Internet Explorer
Search vendor "Microsoft" for product "Internet Explorer"
--
Safe
Ibm
Search vendor "Ibm"
Star Command Center
Search vendor "Ibm" for product "Star Command Center"
3.0.5
Search vendor "Ibm" for product "Star Command Center" and version "3.0.5"
-
Affected
in Microsoft
Search vendor "Microsoft"
Internet Explorer
Search vendor "Microsoft" for product "Internet Explorer"
--
Safe
Ibm
Search vendor "Ibm"
Star Command Center
Search vendor "Ibm" for product "Star Command Center"
3.0.6
Search vendor "Ibm" for product "Star Command Center" and version "3.0.6"
-
Affected
in Microsoft
Search vendor "Microsoft"
Internet Explorer
Search vendor "Microsoft" for product "Internet Explorer"
--
Safe
Ibm
Search vendor "Ibm"
Star Command Center
Search vendor "Ibm" for product "Star Command Center"
3.0.7
Search vendor "Ibm" for product "Star Command Center" and version "3.0.7"
-
Affected
in Microsoft
Search vendor "Microsoft"
Internet Explorer
Search vendor "Microsoft" for product "Internet Explorer"
--
Safe