Description
Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/32576
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/32847
Broken Link vdb-entry
x_refsource_osvdb
http://www.osvdb.org/50369
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PK69316
Scores
EPSS
0.0196
EPSS Percentile
78.2%
Details
CWE
CWE-79
Status
published
Products (1)
ibm/rational_clearquest
7.0.0.0 - 7.0.0.4
Published
Dec 05, 2008
Tracked Since
Feb 18, 2026