CVE-2007-4348: XSS
Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log entries in a dsmerror.log file that is accessible through a certain web interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4348?
CVE-2007-4348 has been classified as a moderate severity cross-site scripting vulnerability.
How do I fix CVE-2007-4348?
To mitigate CVE-2007-4348, upgrade the IBM Tivoli Storage Manager Client to a version greater than 5.4.1.2 or 5.3.5.3.
What systems are affected by CVE-2007-4348?
CVE-2007-4348 affects IBM Tivoli Storage Manager Client versions 5.3.5.3 and 5.4.1.2 on Windows.
What kind of attacks can be executed through CVE-2007-4348?
Attackers can exploit CVE-2007-4348 to inject arbitrary web scripts or HTML into the affected system.
Is CVE-2007-4348 still a significant risk today?
CVE-2007-4348 remains a risk as organizations may still be using vulnerable versions of the IBM Tivoli Storage Manager Client.