cbcvebase.
CVE-2013-0499
published 2013-05-28

CVE-2013-0499: Cross-site scripting (XSS) vulnerability in the echo functionality on IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0, 4.0.1, 4.0.2, and 5.0.0…

PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.21%
64.8th percentile
Cross-site scripting (XSS) vulnerability in the echo functionality on IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0, 4.0.1, 4.0.2, and 5.0.0 allows remote attackers to inject arbitrary web script or HTML via a SOAP message, as demonstrated by the XML Firewall, Multi Protocol Gateway (MPGW), Web Service Proxy, and Web Token services.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
ibmwebsphere_datapower_b2b_appliance_xb62_firmware
ibmwebsphere_datapower_b2b_appliance_xb62_firmware
ibmwebsphere_datapower_b2b_appliance_xb62_firmware
ibmwebsphere_datapower_b2b_appliance_xb62_firmware
ibmwebsphere_datapower_b2b_appliance_xb62_firmware
ibmwebsphere_datapower_integration_appliance_xi50_firmware
ibmwebsphere_datapower_integration_appliance_xi50_firmware
ibmwebsphere_datapower_integration_appliance_xi50_firmware
ibmwebsphere_datapower_integration_appliance_xi50_firmware
ibmwebsphere_datapower_integration_appliance_xi50_firmware
ibmwebsphere_datapower_integration_appliance_xi52_firmware
ibmwebsphere_datapower_integration_appliance_xi52_firmware
ibmwebsphere_datapower_integration_appliance_xi52_firmware
ibmwebsphere_datapower_integration_appliance_xi52_firmware
ibmwebsphere_datapower_integration_appliance_xi52_firmware
ibmwebsphere_datapower_integration_appliance_xi52_virtual_edition_firmware
ibmwebsphere_datapower_integration_appliance_xi52_virtual_edition_firmware
ibmwebsphere_datapower_integration_appliance_xi52_virtual_edition_firmware
ibmwebsphere_datapower_integration_appliance_xi52_virtual_edition_firmware
ibmwebsphere_datapower_integration_appliance_xi52_virtual_edition_firmware
ibmwebsphere_datapower_service_gateway_xg45_firmware
ibmwebsphere_datapower_service_gateway_xg45_firmware
ibmwebsphere_datapower_service_gateway_xg45_firmware
ibmwebsphere_datapower_service_gateway_xg45_firmware
ibmwebsphere_datapower_service_gateway_xg45_firmware
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.