Vulnerability Details CVE-2015-7459
Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108355.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.2%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2015-7459
-
cpe:2.3:a:ibm:connections:1.0.0.0
-
cpe:2.3:a:ibm:connections:1.0.1.0
-
cpe:2.3:a:ibm:connections:1.0.2.0
-
cpe:2.3:a:ibm:connections:2.0.0.0
-
cpe:2.3:a:ibm:connections:2.0.1.0
-
cpe:2.3:a:ibm:connections:2.0.1.1
-
cpe:2.3:a:ibm:connections:2.5.0.0
-
cpe:2.3:a:ibm:connections:2.5.0.1
-
cpe:2.3:a:ibm:connections:2.5.0.2
-
cpe:2.3:a:ibm:connections:2.5.0.3
-
cpe:2.3:a:ibm:connections:3.0.0.0
-
cpe:2.3:a:ibm:connections:3.0.1.0
-
cpe:2.3:a:ibm:connections:3.0.1.1
-
cpe:2.3:a:ibm:connections:4.0.0.0
-
cpe:2.3:a:ibm:connections:4.5.0.0
-
cpe:2.3:a:ibm:connections:5.0.0.0