CVE-2012-5949
Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject content, and conduct phishing attacks, via vectors involving (1) the html/en/default/ directory, (2)…
Does this matter?
Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject content, and conduct phishing attacks, via vectors involving (1) the html/en/default/ directory, (2) birt/frameset, (3) WebProcess.srv, (4) sqa/html/en/default/reportTemplate/reportTemplateOrderCols.jsp, or (5) a/html/en/default/om2/omObjectFinder.jsp.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.15% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- ibm/tririga application platform
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21628851Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21628852Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80629
- http://www-01.ibm.com/support/docview.wss?uid=swg21628851Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21628852Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80629
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.