CVSS2
Attack Vector
ADJACENT_NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:A/AC:M/Au:S/C:N/I:P/A:N
AI Score
Confidence
High
EPSS
Percentile
26.3%
Cross-site scripting (XSS) vulnerability in IBM Document Connect for Application Support Facility (aka DC4ASF) before 1.0.0.1218 in Application Support Facility (ASF) 3.4 for z/OS on Windows, Linux, and AIX allows remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | application_support_facility | 3.4.0 | cpe:2.3:a:ibm:application_support_facility:3.4.0:-:*:*:*:aix:*:* |
ibm | application_support_facility | 3.4.0 | cpe:2.3:a:ibm:application_support_facility:3.4.0:-:*:*:*:linux_kernel:*:* |
ibm | application_support_facility | 3.4.0 | cpe:2.3:a:ibm:application_support_facility:3.4.0:-:*:*:*:windows:*:* |
ibm | application_support_facility | 3.4.0 | cpe:2.3:a:ibm:application_support_facility:3.4.0:-:*:*:*:z\/os:*:* |
ibm | document_connect_for_application_support_facility | * | cpe:2.3:a:ibm:document_connect_for_application_support_facility:*:*:*:*:*:*:*:* |