CVE-2013-6327: IBM Sterling Connect Enterprise HTTP Option

Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the HTTP Option in IBM Sterling Connect:Enterprise 1.3 before 1.3.0.2 iFix 1 and 1.4 before 1.4.0.0 iFix 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "cross-frame scripting" issue.

Affected products

  • IBM Sterling Connect Enterprise HTTP Option: version 1.3.02 only; version 1.4.00 only

Published 2013-12-17. Last modified 2026-06-17.