CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
AI Score
Confidence
High
EPSS
Percentile
68.9%
Multiple cross-site scripting (XSS) vulnerabilities in the JSF Widget Library Runtime in IBM Rational Application Developer for WebSphere Software before 7.0.0.10 and Rational Software Architect before 7.0.0.10 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) the JSF Tree Control and (2) the JavaScript Resource Servlet.
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | rational_application_developer_for_websphere | 7.0 | cpe:2.3:a:ibm:rational_application_developer_for_websphere:7.0:*:*:*:*:*:*:* |
ibm | rational_application_developer_for_websphere | 7.0.0.1 | cpe:2.3:a:ibm:rational_application_developer_for_websphere:7.0.0.1:*:*:*:*:*:*:* |
ibm | rational_application_developer_for_websphere | 7.0.0.2 | cpe:2.3:a:ibm:rational_application_developer_for_websphere:7.0.0.2:*:*:*:*:*:*:* |
ibm | rational_application_developer_for_websphere | 7.0.0.3 | cpe:2.3:a:ibm:rational_application_developer_for_websphere:7.0.0.3:*:*:*:*:*:*:* |
ibm | rational_application_developer_for_websphere | 7.0.0.4 | cpe:2.3:a:ibm:rational_application_developer_for_websphere:7.0.0.4:*:*:*:*:*:*:* |
ibm | rational_application_developer_for_websphere | 7.0.0.5 | cpe:2.3:a:ibm:rational_application_developer_for_websphere:7.0.0.5:*:*:*:*:*:*:* |
ibm | rational_application_developer_for_websphere | 7.0.0.6 | cpe:2.3:a:ibm:rational_application_developer_for_websphere:7.0.0.6:*:*:*:*:*:*:* |
ibm | rational_application_developer_for_websphere | 7.0.0.7 | cpe:2.3:a:ibm:rational_application_developer_for_websphere:7.0.0.7:*:*:*:*:*:*:* |
ibm | rational_application_developer_for_websphere | 7.0.0.8 | cpe:2.3:a:ibm:rational_application_developer_for_websphere:7.0.0.8:*:*:*:*:*:*:* |
ibm | rational_application_developer_for_websphere | 7.0.0.9 | cpe:2.3:a:ibm:rational_application_developer_for_websphere:7.0.0.9:*:*:*:*:*:*:* |
secunia.com/advisories/37442
www-01.ibm.com/support/docview.wss?uid=swg1PK90616
www-01.ibm.com/support/docview.wss?uid=swg1PK94324
www-01.ibm.com/support/docview.wss?uid=swg27012378
www-01.ibm.com/support/docview.wss?uid=swg27012558
www.osvdb.org/60319
www.securityfocus.com/bid/37083
exchange.xforce.ibmcloud.com/vulnerabilities/54360