Lucene search

K
cveMitreCVE-2010-2985
HistoryAug 10, 2010 - 12:23 p.m.

CVE-2010-2985

2010-08-1012:23:06
CWE-79
mitre
web.nvd.nist.gov
22
cve-2010-2985
xss
ibm
websphere
service registry
repository
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.028

Percentile

90.8%

Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the searchTerm parameter to ServiceRegistry/HelpSearch.do or (2) the queryItems[0].value parameter to ServiceRegistry/QueryWizardProcessStep1.do.

Affected configurations

Nvd
Node
ibmwebsphere_service_registry_and_repositoryMatch6.3.0
VendorProductVersionCPE
ibmwebsphere_service_registry_and_repository6.3.0cpe:2.3:a:ibm:websphere_service_registry_and_repository:6.3.0:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.028

Percentile

90.8%

Related for CVE-2010-2985