VulnerabilityModified
CVE-2012-2169
Cross-site scripting (XSS) vulnerability in the file-upload functionality in the Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 allows remote authenticated users to inject arbitrary web script or HTML via the File Description field.
LOW 3.5EPSS 1.40%
Does this matter?
Lower severity and a low EPSS score (1.40%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the file-upload functionality in the Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 allows remote authenticated users to inject arbitrary web script or HTML via the File Description field.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- ibm/rational clearquest
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM62762Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21607783Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75049
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM62762Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21607783Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75049
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.