CVE-2009-3745
IBM Rational AppScan Enterprise Edition 5.5.0.2 - Cross-Site Scripting via Help Page Query String
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the help pages in IBM Rational AppScan Enterprise Edition 5.5.0.2 allows remote attackers to inject arbitrary web script or HTML via the query string.
References (6)
Core 6
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/37093
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/2974
Patch x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg24024704
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/53821
Exploit vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PK97516
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/36734
Scores
EPSS
0.0129
EPSS Percentile
67.1%
Details
CWE
CWE-79
Status
published
Products (1)
ibm/rational_appscan
5.5.0.2
Published
Oct 22, 2009
Tracked Since
Feb 18, 2026