CVE-2007-1468: XSS
Published Mar 16, 2007
·Updated
Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest (CQ) Web 7.0.0.0 allows remote attackers to inject arbitrary web script or HTML via an attachment to a defect log entry.
Affected Software
1 affected component
IBM Rational ClearQuest=7.0.0.0
Event History
Mar 16, 2007
CVE Published
09:19 PM
Mar 17, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1468?
CVE-2007-1468 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2007-1468?
To fix CVE-2007-1468, update IBM Rational ClearQuest to a patched version that addresses the XSS vulnerability.
3
What systems are affected by CVE-2007-1468?
CVE-2007-1468 specifically affects IBM Rational ClearQuest version 7.0.0.0.
4
What type of attack does CVE-2007-1468 enable?
CVE-2007-1468 allows remote attackers to execute arbitrary web script or HTML in the context of the user's session.
5
Can CVE-2007-1468 be exploited through attachments?
Yes, CVE-2007-1468 can be exploited by injecting malicious scripts via attachments to defect log entries.