Show plain JSON{"id": "CVE-2013-0592", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 3.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:S/C:P/I:N/A:N", "authentication": "SINGLE", "integrityImpact": "NONE", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "LOW", "obtainAllPrivilege": false, "exploitabilityScore": 6.8, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "CHANGED", "version": "3.0", "baseScore": 5.4, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "LOW"}, "impactScore": 2.7, "exploitabilityScore": 2.3}]}, "published": "2018-07-11T16:29:00.297", "references": [{"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/83815", "tags": ["VDB Entry", "Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "https://www-01.ibm.com/support/docview.wss?uid=swg21671622", "tags": ["Patch", "Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/83815", "tags": ["VDB Entry", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www-01.ibm.com/support/docview.wss?uid=swg21671622", "tags": ["Patch", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 83815."}, {"lang": "es", "value": "Vulnerabilidad Cross-Site Scripting (XSS) en IBM iNotes en versiones anteriores a la 8.5.3 Fix Pack 6 y versiones 9.x anteriores a la 9.0.1 permite a atacantes remotos inyectar scripts web o HTML arbitrarios utilizando vectores no especificados. IBM X-Force ID: 83815."}], "lastModified": "2024-11-21T01:47:49.150", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:inotes:8.0.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E3A3B1B1-D7AD-439B-B34E-47A5711A2C64"}, {"criteria": "cpe:2.3:a:ibm:inotes:8.0.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0412E062-0ED4-41F3-8F32-807A5AA3FE04"}, {"criteria": "cpe:2.3:a:ibm:inotes:8.0.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B43A49D7-6046-443C-96F5-E00905B22B5C"}, {"criteria": "cpe:2.3:a:ibm:inotes:8.5.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "16FE6AAC-7B25-40EA-9D25-128D743F18A9"}, {"criteria": "cpe:2.3:a:ibm:inotes:8.5.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "49FF4C09-76B3-4CCA-9EBA-530B4CB0314D"}, {"criteria": "cpe:2.3:a:ibm:inotes:8.5.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B097CA3C-2ABA-489E-86C1-EEF891AF7094"}, {"criteria": "cpe:2.3:a:ibm:inotes:8.5.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A34CFCD5-D0F8-46E4-BA5F-24AA9CD378A6"}, {"criteria": "cpe:2.3:a:ibm:inotes:9.0.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "975E8316-D4C3-40B7-8E57-E871D0327271"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@us.ibm.com"}