CVE-2013-6738
published 2014-04-24CVE-2013-6738: Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.08%
79.4th percentile
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | smartcloud_analytics_log_analysis | — | — |
| ibm | smartcloud_analytics_log_analysis | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM SmartCloud Analytics Log Analysis prior 1.2.0 Authorization Query cross site scripting (Nessus ID 76967 / ID 124155)
vuldb·2026-05-11·CVSS 4.3
CVE-2013-6738 [MEDIUM] IBM SmartCloud Analytics Log Analysis prior 1.2.0 Authorization Query cross site scripting (Nessus ID 76967 / ID 124155)
A vulnerability has been found in IBM SmartCloud Analytics Log Analysis and classified as problematic. The affected element is an unknown function of the component Authorization. Performing a manipulation of the argument Query results in cross site scripting.
This vulnerability is identified as CVE-2013-6738. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
GHSA
GHSA-cf9r-vm22-cxhg: Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1
ghsa_unreviewed·2022-05-17
CVE-2013-6738 [MEDIUM] CWE-79 GHSA-cf9r-vm22-cxhg: Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg1IV57425http://www-01.ibm.com/support/docview.wss?uid=swg21669137http://www-01.ibm.com/support/docview.wss?uid=swg21669554http://www-01.ibm.com/support/docview.wss?uid=swg21676091http://www-01.ibm.com/support/docview.wss?uid=swg21676092http://www.securityfocus.com/bid/67051https://exchange.xforce.ibmcloud.com/vulnerabilities/89854http://www-01.ibm.com/support/docview.wss?uid=swg1IV57425http://www-01.ibm.com/support/docview.wss?uid=swg21669137http://www-01.ibm.com/support/docview.wss?uid=swg21669554http://www-01.ibm.com/support/docview.wss?uid=swg21676091http://www-01.ibm.com/support/docview.wss?uid=swg21676092http://www.securityfocus.com/bid/67051https://exchange.xforce.ibmcloud.com/vulnerabilities/89854
2014-04-24
Published