CVE-2013-0499 - CVE House
Back to Database
Status published Medium CVE-2013-0499

Cross-site scripting (XSS) vulnerability in the echo functionality on IBM...

Vulnerability Description

Cross-site scripting (XSS) vulnerability in the echo functionality on IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0, 4.0.1, 4.0.2, and 5.0.0 allows remote attackers to inject arbitrary web script or HTML via a SOAP message, as demonstrated by the XML Firewall, Multi Protocol Gateway (MPGW), Web Service Proxy, and Web Token services.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-0499

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

websphere datapower xc10 appliance firmware, websphere datapower xc10 appliance, websphere datapower service gateway xg45 virtual edition firmware, websphere datapower service gateway xg45 virtual edition, websphere datapower service gateway xg45 firmware, websphere datapower service gateway xg45, websphere datapower integration appliance xi52 virtual edition firmware, websphere datapower integration appliance xi52 virtual edition, websphere datapower integration appliance xi52 firmware, websphere datapower integration appliance xi52, websphere datapower integration appliance xi50 firmware, websphere datapower integration appliance xi50, websphere datapower b2b appliance xb62 firmware, websphere datapower b2b appliance xb62
Vulnerable Versions:
3.8.2, 4.0, 4.0.1, 4.0.2, 5.0.0

Timeline

Official Publish: May 28th, 2013
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.