Vulnerability Name: | CVE-2008-5325 (CCN-47164) | ||||||||
Assigned: | 2008-12-01 | ||||||||
Published: | 2008-12-01 | ||||||||
Updated: | 2018-11-08 | ||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-5325 Source: CCN Type: SA32847 IBM Rational ClearQuest Multiple Vulnerabilities Source: SECUNIA Type: Third Party Advisory 32847 Source: CCN Type: IBM Web site Rational ClearQuest Source: AIXAPAR Type: Vendor Advisory PK69316 Source: CCN Type: IBM APAR PK69316 CQ Web Cross-site scripting vulnerability Source: OSVDB Type: Broken Link 50369 Source: CCN Type: OSVDB ID: 50369 IBM Rational ClearCase RWP Server VOB Page Unspecified XSS Source: BID Type: Third Party Advisory, VDB Entry 32576 Source: CCN Type: BID-32576 IBM Rational ClearQuest Web Multiple Unspecified Cross Site Scripting Vulnerabilities Source: XF Type: UNKNOWN clearquest-cqweb-xss-var2(47164) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |