Lucene search

K
cveMitreCVE-2010-0640
HistoryFeb 24, 2010 - 6:30 p.m.

CVE-2010-0640

2010-02-2418:30:00
CWE-79
mitre
web.nvd.nist.gov
30
cve-2010-0640
cross-site scripting
xss
ca ehealth performance manager
nvd

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.005

Percentile

77.6%

Cross-site scripting (XSS) vulnerability in CA eHealth Performance Manager 6.0.x through 6.2.x, when malicious HTML detection is disabled, allows remote attackers to inject arbitrary web script or HTML via a crafted request.

Affected configurations

Nvd
Node
caehealth_performance_managerMatch6.0
OR
caehealth_performance_managerMatch6.1
OR
caehealth_performance_managerMatch6.2
VendorProductVersionCPE
caehealth_performance_manager6.0cpe:2.3:a:ca:ehealth_performance_manager:6.0:*:*:*:*:*:*:*
caehealth_performance_manager6.1cpe:2.3:a:ca:ehealth_performance_manager:6.1:*:*:*:*:*:*:*
caehealth_performance_manager6.2cpe:2.3:a:ca:ehealth_performance_manager:6.2:*:*:*:*:*:*:*

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.005

Percentile

77.6%

Related for CVE-2010-0640