Lucene search

K
cveMitreCVE-2007-4592
HistoryMar 20, 2008 - 12:44 a.m.

CVE-2007-4592

2008-03-2000:44:00
CWE-79
mitre
web.nvd.nist.gov
26
4
ibm
rational clearquest
xss
vulnerabilities
web interface
security
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.6

Confidence

High

EPSS

0.004

Percentile

74.2%

Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, and 7.0.1.1_iFix01 allow remote attackers to inject arbitrary web script or HTML via the (1) contextid, (2) username, (3) userNameVal, and (4) schema parameters to the login component.

Affected configurations

Nvd
Node
ibmrational_clearquestRange≀2003-06-16
OR
ibmrational_clearquestMatch7.0.1
OR
ibmrational_clearquestMatch7.0.1.1
OR
ibmrational_clearquestMatch7.0.2
VendorProductVersionCPE
ibmrational_clearquest*cpe:2.3:a:ibm:rational_clearquest:*:*:*:*:*:*:*:*
ibmrational_clearquest7.0.1cpe:2.3:a:ibm:rational_clearquest:7.0.1:*:*:*:*:*:*:*
ibmrational_clearquest7.0.1.1cpe:2.3:a:ibm:rational_clearquest:7.0.1.1:*:*:*:*:*:*:*
ibmrational_clearquest7.0.2cpe:2.3:a:ibm:rational_clearquest:7.0.2:*:*:*:*:*:*:*

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.6

Confidence

High

EPSS

0.004

Percentile

74.2%