what you don't know can hurt you

IBM iNotes Cross Site Scripting

IBM iNotes Cross Site Scripting
Posted Aug 27, 2013
Authored by Alexander Klink

IBM Lotus iNotes suffered from four cross site scripting vulnerabilities.

tags | advisory, vulnerability, xss
advisories | CVE-2013-0590, CVE-2013-0591, CVE-2013-0595
MD5 | a668564eb96884f679abb44f540211b2

IBM iNotes Cross Site Scripting

Change Mirror Download
Abstract

IBM® Lotus iNotes® 8.5.x contains four cross-site scripting vulnerabilities. The fixes for these issues are available in IBM® Lotus Domino® release 8.5.3 Fixpack 5.
Content

IBM iNotes has four cross-site scripting vulnerabilities. Two of the vulnerabilities share the same CVE ID (CVE-2013-0595). These vulnerabilities could allow a remote unauthenticated attacker to expose user personal data.
VULNERABILITY DETAILS: IBM iNotes Cross-site Scripting vulnerabilities

CVE ID: CVE-2013-0590, CVE-2013-0591, CVE-2013-0595

DESCRIPTION: A remote unauthenticated attacker could exploit a security vulnerability in IBM iNotes to expose user personal data.

CVSS:

CVE ID: CVE-2013-0590
CVSS Base Score: 3.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/83814 for the current score.
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/AU:S/C:N/I:P/A:N)

Access Vector: Network Access Complexity: Medium
Authentication: Single Confidentiality Impact: None
Integrity Impact: Partial Availability Impact: None


CVE ID: CVE-2013-0591
CVSS Base Score: 3.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/83381 for the current score.
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/AU:S/C:N/I:P/A:N)

Access Vector: Network Access Complexity: Medium
Authentication: Single Confidentiality Impact: None
Integrity Impact: Partial Availability Impact: None


CVE ID: CVE-2013-0595
CVSS Base Score: 4.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/83431 for the current score.
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/AU:N/C:N/I:P/A:N)

Access Vector: Network Access Complexity: Medium
Authentication: No Confidentiality Impact: None
Integrity Impact: Partial Availability Impact: None

AFFECTED PLATFORMS:

IBM iNotes 8.5.x

REMEDIATION:

Fix:

All three of these issues are being tracked through SPR #PTHN95XNR3. The fix is available in IBM Domino release 8.5.3 Fix Pack 5, which can be accessed here:

http://www-01.ibm.com/support/docview.wss?uid=swg24032242

Workaround:

None

Mitigation(s):

None



REFERENCES:

CVE-2013-0590
CVE-2013-0591
CVE-2013-0595
Complete CVSS Guide
On-line Calculator V2
X-Force Vulnerability Database (http://xforce.iss.net/xforce/xfdb/83814,http://xforce.iss.net/xforce/xfdb/83381 and http://xforce.iss.net/xforce/xfdb/83431)



RELATED INFORMATION:

IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog

ACKNOWLEDGEMENT:
These vulnerabilities were reported to IBM by Alexander Klink of n.runs AG.


Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

February 2015

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    2 Files
  • 2
    Feb 2nd
    17 Files
  • 3
    Feb 3rd
    15 Files
  • 4
    Feb 4th
    16 Files
  • 5
    Feb 5th
    14 Files
  • 6
    Feb 6th
    4 Files
  • 7
    Feb 7th
    0 Files
  • 8
    Feb 8th
    0 Files
  • 9
    Feb 9th
    0 Files
  • 10
    Feb 10th
    0 Files
  • 11
    Feb 11th
    0 Files
  • 12
    Feb 12th
    0 Files
  • 13
    Feb 13th
    0 Files
  • 14
    Feb 14th
    0 Files
  • 15
    Feb 15th
    0 Files
  • 16
    Feb 16th
    0 Files
  • 17
    Feb 17th
    0 Files
  • 18
    Feb 18th
    0 Files
  • 19
    Feb 19th
    0 Files
  • 20
    Feb 20th
    0 Files
  • 21
    Feb 21st
    0 Files
  • 22
    Feb 22nd
    0 Files
  • 23
    Feb 23rd
    0 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2015 Packet Storm. All rights reserved.

close