Vulnerability Details CVE-2012-5949
Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject content, and conduct phishing attacks, via vectors involving (1) the html/en/default/ directory, (2) birt/frameset, (3) WebProcess.srv, (4) sqa/html/en/default/reportTemplate/reportTemplateOrderCols.jsp, or (5) a/html/en/default/om2/omObjectFinder.jsp.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.0%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2012-5949
-
cpe:2.3:a:ibm:tririga_application_platform:2.1
-
cpe:2.3:a:ibm:tririga_application_platform:2.5
-
cpe:2.3:a:ibm:tririga_application_platform:2.6
-
cpe:2.3:a:ibm:tririga_application_platform:2.7
-
cpe:2.3:a:ibm:tririga_application_platform:3.0
-
cpe:2.3:a:ibm:tririga_application_platform:3.1
-
cpe:2.3:a:ibm:tririga_application_platform:3.2
-
cpe:2.3:a:ibm:tririga_application_platform:3.2.1
-
cpe:2.3:a:ibm:tririga_application_platform:8.0