ID

VAR-201510-0730


CVE

CVE-2015-4973


TITLE

IBM Multi-Enterprise Integration Gateway and B2B Advanced Communications Cross-Site Scripting Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2015-06313 // CNNVD: CNNVD-201509-463

DESCRIPTION

Cross-site scripting (XSS) vulnerability in IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. IBM B2B Advanced Communications is a B2B advanced communications product. Multiple IBM products are prone to an unspecified cross-site scripting vulnerability because it fails to sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks

Trust: 2.43

sources: NVD: CVE-2015-4973 // JVNDB: JVNDB-2015-005097 // CNVD: CNVD-2015-06313 // BID: 76538

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-06313

AFFECTED PRODUCTS

vendor:ibmmodel:b2b advanced communicationsscope:eqversion:1.0.0.2

Trust: 2.7

vendor:ibmmodel:b2b advanced communicationsscope:eqversion:1.0.0.3

Trust: 1.9

vendor:ibmmodel:b2b advanced communicationsscope:eqversion:1.0.0.1

Trust: 1.6

vendor:ibmmodel:b2b advanced communicationsscope:eqversion:1.0.0.3_2

Trust: 0.8

vendor:ibmmodel:b2b advanced communicationsscope:ltversion:1.0.0.3

Trust: 0.8

vendor:ibmmodel:multi-enterprise integration gatewayscope:eqversion:1.0.0.1 for up to 1.x

Trust: 0.8

vendor:ibmmodel:multi-enterprise integration gatewayscope:eqversion:1.0-1.0.0.1

Trust: 0.6

vendor:ibmmodel:b2b advanced communicationsscope:eqversion:1.0.0.2-1.0.0.3

Trust: 0.6

vendor:ibmmodel:multi-enterprise integration gatewayscope:eqversion:1.0.0.1

Trust: 0.3

vendor:ibmmodel:multi-enterprise integration gatewayscope:eqversion:1.0

Trust: 0.3

sources: CNVD: CNVD-2015-06313 // BID: 76538 // JVNDB: JVNDB-2015-005097 // CNNVD: CNNVD-201509-463 // NVD: CVE-2015-4973

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-4973
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-4973
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-06313
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201509-463
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2015-4973
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-06313
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2015-06313 // JVNDB: JVNDB-2015-005097 // CNNVD: CNNVD-201509-463 // NVD: CVE-2015-4973

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.8

sources: JVNDB: JVNDB-2015-005097 // NVD: CVE-2015-4973

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201509-463

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201509-463

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-005097

PATCH

title:1964806url:http://www-01.ibm.com/support/docview.wss?uid=swg21964806

Trust: 0.8

title:Patch for IBM Multi-Enterprise Integration Gateway and B2B Advanced Communications cross-site scripting vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/64750

Trust: 0.6

title:IBM Multi-Enterprise Integration Gateway and B2B Advanced Communications Fixes for cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=57787

Trust: 0.6

sources: CNVD: CNVD-2015-06313 // JVNDB: JVNDB-2015-005097 // CNNVD: CNNVD-201509-463

EXTERNAL IDS

db:NVDid:CVE-2015-4973

Trust: 3.3

db:BIDid:76538

Trust: 0.9

db:JVNDBid:JVNDB-2015-005097

Trust: 0.8

db:CNVDid:CNVD-2015-06313

Trust: 0.6

db:CNNVDid:CNNVD-201509-463

Trust: 0.6

sources: CNVD: CNVD-2015-06313 // BID: 76538 // JVNDB: JVNDB-2015-005097 // CNNVD: CNNVD-201509-463 // NVD: CVE-2015-4973

REFERENCES

url:http://www-01.ibm.com/support/docview.wss?uid=swg21964806

Trust: 2.5

url:http://www-01.ibm.com/support/docview.wss?uid=swg1it10705

Trust: 1.6

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-4973

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-4973

Trust: 0.8

url:http://www.securityfocus.com/bid/76538

Trust: 0.6

url:http://www.ibm.com/

Trust: 0.3

sources: CNVD: CNVD-2015-06313 // BID: 76538 // JVNDB: JVNDB-2015-005097 // CNNVD: CNNVD-201509-463 // NVD: CVE-2015-4973

CREDITS

IBM

Trust: 0.9

sources: BID: 76538 // CNNVD: CNNVD-201509-463

SOURCES

db:CNVDid:CNVD-2015-06313
db:BIDid:76538
db:JVNDBid:JVNDB-2015-005097
db:CNNVDid:CNNVD-201509-463
db:NVDid:CVE-2015-4973

LAST UPDATE DATE

2025-04-13T23:25:11.633000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-06313date:2015-10-09T00:00:00
db:BIDid:76538date:2015-08-26T00:00:00
db:JVNDBid:JVNDB-2015-005097date:2015-10-08T00:00:00
db:CNNVDid:CNNVD-201509-463date:2015-09-23T00:00:00
db:NVDid:CVE-2015-4973date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-06313date:2015-10-09T00:00:00
db:BIDid:76538date:2015-08-26T00:00:00
db:JVNDBid:JVNDB-2015-005097date:2015-10-08T00:00:00
db:CNNVDid:CNNVD-201509-463date:2015-08-26T00:00:00
db:NVDid:CVE-2015-4973date:2015-10-06T01:59:14.470