Vulnerability Name: | CVE-2007-5798 (CCN-38177) | ||||||||
Assigned: | 2007-10-30 | ||||||||
Published: | 2007-10-30 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to inject arbitrary web script or HTML via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-5798 Source: OSVDB Type: UNKNOWN 41618 Source: CCN Type: SA27448 IBM WebSphere "uddigui/navigateTree.do" Cross-Site Scripting and Request Forgery Source: SECUNIA Type: Vendor Advisory 27448 Source: CCN Type: SECTRACK ID: 1018884 IBM WebSphere Application Server Input Validation Hole in `uddigui/navigateTree.do` Page Permits Cross-Site Scripting Attacks Source: AIXAPAR Type: UNKNOWN PK50245 Source: CCN Type: IBM APAR PK50245 VALIDATION NEEDED FOR PARAMETERS THAT ARE PASSED TO THE NAVIGATETREE.DO PAGE IN THE UDDI USER CONSOLE Source: CCN Type: OSVDB ID: 41618 IBM WebSphere uddigui/navigateTree.do Multiple Parameter XSS Source: BID Type: UNKNOWN 26276 Source: CCN Type: BID-26276 IBM WebSphere Application Server UDDI Console Multiple Input Validation Vulnerabilities Source: SECTRACK Type: UNKNOWN 1018884 Source: VUPEN Type: UNKNOWN ADV-2007-3672 Source: XF Type: UNKNOWN websphere-navigatetree-xss(38177) Source: XF Type: UNKNOWN websphere-navigatetree-xss(38177) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |