CVE-2007-4592: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2iFix01, and 7.0.1.1iFix01 allow remote attackers to inject arbitrary web script or HTML via the (1) contextid, (2) username, (3) userNameVal, and (4) schema parameters to the login component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4592?
CVE-2007-4592 is considered a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2007-4592?
To fix CVE-2007-4592, upgrade to IBM Rational ClearQuest versions 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, or 7.0.1.1_iFix01.
What software is affected by CVE-2007-4592?
CVE-2007-4592 affects IBM Rational ClearQuest versions before 2003.06.16 and specifically versions 7.0.1.1 and 7.0.1.
What types of vulnerabilities are present in CVE-2007-4592?
CVE-2007-4592 contains multiple cross-site scripting (XSS) vulnerabilities.
Can CVE-2007-4592 be exploited remotely?
Yes, CVE-2007-4592 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.