CVE-2009-4052
Multiple cross-site scripting (XSS) vulnerabilities in the JSF Widget Library Runtime in IBM Rational Application Developer for WebSphere Software before 7.0.0.10 and Rational Software Architect before 7.0.0.10 allow remote attackers to inject arbitrary…
Does this matter?
Lower severity and a low EPSS score (1.98%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the JSF Widget Library Runtime in IBM Rational Application Developer for WebSphere Software before 7.0.0.10 and Rational Software Architect before 7.0.0.10 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) the JSF Tree Control and (2) the JavaScript Resource Servlet.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.98% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- ibm/rational application developer for websphere · ibm/rational software architect
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/37442Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK90616Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK94324Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg27012378Patch
- http://www-01.ibm.com/support/docview.wss?uid=swg27012558Patch
- http://www.osvdb.org/60319
- http://www.securityfocus.com/bid/37083
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54360
- http://secunia.com/advisories/37442Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK90616Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK94324Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg27012378Patch
- http://www-01.ibm.com/support/docview.wss?uid=swg27012558Patch
- http://www.osvdb.org/60319
- http://www.securityfocus.com/bid/37083
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54360
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.