Vulnerability Details CVE-2008-5330
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO of a URI associated with a VOB page.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.022
EPSS Ranking 83.8%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2008-5330
-
cpe:2.3:a:ibm:rational_clearquest:7.0.0.0
-
cpe:2.3:a:ibm:rational_clearquest:7.0.0.1
-
cpe:2.3:a:ibm:rational_clearquest:7.0.0.2
-
cpe:2.3:a:ibm:rational_clearquest:7.0.0.3
-
cpe:2.3:a:ibm:rational_clearquest:7.0.1
-
cpe:2.3:a:ibm:rational_clearquest:7.0.1.1
-
cpe:2.3:a:ibm:rational_clearquest:7.0.1.2