Vulnerability Name: | CVE-2009-3730 (CCN-53812) | ||||||||
Assigned: | 2009-10-15 | ||||||||
Published: | 2009-10-15 | ||||||||
Updated: | 2009-10-27 | ||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in the ReqWeb Help feature (aka the Web Client Help system) in IBM Rational RequisitePro 7.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the operation parameter to ReqWebHelp/advanced/workingSet.jsp, or the (2) searchWord, (3) maxHits, (4) scopedSearch, or (5) scope parameter to ReqWebHelp/basic/searchView.jsp. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-3730 Source: OSVDB Type: UNKNOWN 59088 Source: OSVDB Type: UNKNOWN 59089 Source: CCN Type: SA37052 IBM Rational RequisitePro ReqWebHelp Cross-Site Scripting Source: SECUNIA Type: Vendor Advisory 37052 Source: AIXAPAR Type: Exploit, Patch, Vendor Advisory PK83895 Source: CCN Type: IBM APAR PK83895 REQWEB HELP IS VULNERABLE TO CROSS-SITE SCRIPTING ATTACKS Source: CCN Type: OSVDB ID: 59088 IBM Rational RequisitePro ReqWeb Help Feature ReqWebHelp/advanced/workingSet.jsp operation Parameter XSS Source: CCN Type: OSVDB ID: 59089 IBM Rational RequisitePro ReqWeb Help Feature ReqWebHelp/basic/searchView.jsp Multiple Parameter XSS Source: BID Type: Exploit 36721 Source: CCN Type: BID-36721 IBM Rational RequisitePro ReqWebHelp Multiple Cross Site Scripting Vulnerabilities Source: VUPEN Type: Patch, Vendor Advisory ADV-2009-2958 Source: XF Type: UNKNOWN requisitepro-reqwebhelp-xss(53812) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |