Описание
Cross-site scripting (XSS) vulnerability in IBM Document Connect for Application Support Facility (aka DC4ASF) before 1.0.0.1218 in Application Support Facility (ASF) 3.4 for z/OS on Windows, Linux, and AIX allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.0.1204 (включая)
Одно из
cpe:2.3:a:ibm:application_support_facility:3.4.0:-:*:*:*:aix:*:*
cpe:2.3:a:ibm:application_support_facility:3.4.0:-:*:*:*:linux_kernel:*:*
cpe:2.3:a:ibm:application_support_facility:3.4.0:-:*:*:*:windows:*:*
cpe:2.3:a:ibm:application_support_facility:3.4.0:-:*:*:*:z\/os:*:*
cpe:2.3:a:ibm:document_connect_for_application_support_facility:*:*:*:*:*:*:*:*
EPSS
Процентиль: 41%
0.00191
Низкий
2.9 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
почти 4 года назад
Cross-site scripting (XSS) vulnerability in IBM Document Connect for Application Support Facility (aka DC4ASF) before 1.0.0.1218 in Application Support Facility (ASF) 3.4 for z/OS on Windows, Linux, and AIX allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
EPSS
Процентиль: 41%
0.00191
Низкий
2.9 Low
CVSS2
Дефекты
CWE-79