CVE-2007-4348
Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log…
Does this matter?
Lower severity and a low EPSS score (1.22%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log entries in a dsmerror.log file that is accessible through a certain web interface.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- ibm/tivoli storage manager client
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://secunia.com/advisories/27013Vendor Advisory
- http://secunia.com/secunia_research/2007-75/advisoryVendor Advisory
- http://www.securityfocus.com/bid/26221
- http://www.securitytracker.com/id?1018868
- http://www.vupen.com/english/advisories/2007/3635
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38125
- http://secunia.com/advisories/27013Vendor Advisory
- http://secunia.com/secunia_research/2007-75/advisoryVendor Advisory
- http://www.securityfocus.com/bid/26221
- http://www.securitytracker.com/id?1018868
- http://www.vupen.com/english/advisories/2007/3635
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38125
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.