Lucene search

K
cveIbmCVE-2014-6121
HistoryDec 23, 2014 - 2:59 a.m.

CVE-2014-6121

2014-12-2302:59:01
CWE-79
ibm
web.nvd.nist.gov
27
ibm
security
appscan
enterprise
xss
vulnerability
cve-2014-6121

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

36.6%

Cross-site scripting (XSS) vulnerability in IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

Affected configurations

Nvd
Node
ibmsecurity_appscanMatch8.5enterprise
OR
ibmsecurity_appscanMatch8.6enterprise
OR
ibmsecurity_appscanMatch8.7enterprise
OR
ibmsecurity_appscanMatch8.8enterprise
OR
ibmsecurity_appscanMatch9.0enterprise
OR
ibmsecurity_appscanMatch9.0.0.1enterprise
OR
ibmsecurity_appscan_sourceMatch9.0.1enterprise
VendorProductVersionCPE
ibmsecurity_appscan8.5cpe:2.3:a:ibm:security_appscan:8.5:*:*:*:enterprise:*:*:*
ibmsecurity_appscan8.6cpe:2.3:a:ibm:security_appscan:8.6:*:*:*:enterprise:*:*:*
ibmsecurity_appscan8.7cpe:2.3:a:ibm:security_appscan:8.7:*:*:*:enterprise:*:*:*
ibmsecurity_appscan8.8cpe:2.3:a:ibm:security_appscan:8.8:*:*:*:enterprise:*:*:*
ibmsecurity_appscan9.0cpe:2.3:a:ibm:security_appscan:9.0:*:*:*:enterprise:*:*:*
ibmsecurity_appscan9.0.0.1cpe:2.3:a:ibm:security_appscan:9.0.0.1:*:*:*:enterprise:*:*:*
ibmsecurity_appscan_source9.0.1cpe:2.3:a:ibm:security_appscan_source:9.0.1:*:*:*:enterprise:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

36.6%

Related for CVE-2014-6121