{ "id": "CVE-2015-7439", "sourceIdentifier": "psirt@us.ibm.com", "published": "2016-01-27T05:59:00.103", "lastModified": "2016-01-28T00:40:11.773", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Cross-site scripting (XSS) vulnerability in InfoSphere Data Architect (IDA), as distributed in IBM Rational Software Architect 8.5 through 9.5, Rational Software Architect for WebSphere Software (RSA4WS) 8.5 through 9.5, and Rational Software Architect RealTime (RSART) 8.5 through 9.5, allows remote attackers to inject arbitrary web script or HTML via a crafted URL." }, { "lang": "es", "value": "Vulnerabilidad de XSS en InfoSphere Data Architect (IDA), tal como es distribuido en IBM Rational Software Architect 8.5 hasta la versi\u00f3n 9.5, Rational Software Architect for WebSphere Software (RSA4WS) 8.5 hasta la versi\u00f3n 9.5 y Rational Software Architect RealTime (RSART) 8.5 hasta la versi\u00f3n 9.5, permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a trav\u00e9s de una URL manipulada." } ], "metrics": { "cvssMetricV30": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE", "baseScore": 6.1, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 2.8, "impactScore": 2.7 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE", "baseScore": 4.3 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-79" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_realtime:8.5.0:*:*:*:*:*:*:*", "matchCriteriaId": "3B0890FE-EC2C-4B20-9323-233B409D13A5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_realtime:8.5.1:*:*:*:*:*:*:*", "matchCriteriaId": "E0767B4A-4469-4B0C-B0CA-E6C86CA60BE9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_realtime:8.5.1.0:*:*:*:*:*:*:*", "matchCriteriaId": "FE3A64DD-FE9B-48AF-8E09-60F8EE296B62" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_realtime:8.5.5:*:*:*:*:*:*:*", "matchCriteriaId": "4385352D-A26E-40BD-8C86-63BB932753B1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_realtime:8.5.5.1:*:*:*:*:*:*:*", "matchCriteriaId": "5DA897EC-DD94-4827-83BB-E31B6670B0BC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_realtime:8.5.5.2:*:*:*:*:*:*:*", "matchCriteriaId": "66692CE9-0250-4F7F-9FEA-6AB6F7F04D7F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_realtime:8.5.5.3:*:*:*:*:*:*:*", "matchCriteriaId": "1A6B9839-8484-4816-A593-9A71F40303BC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_realtime:8.5.5.4:*:*:*:*:*:*:*", "matchCriteriaId": "DEDE33E8-EB63-442B-BDD5-7DA87CDE1367" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_realtime:9.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "2052A654-468A-4C84-B7BC-C1D3A039A3B7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_realtime:9.0.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "366E70CA-915D-48D4-9843-69433D7A183F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_realtime:9.1.0:*:*:*:*:*:*:*", "matchCriteriaId": "46219905-C2CE-4D4F-8A38-5E4D1C8430C5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_realtime:9.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "F1E37391-F80E-4F75-B7EA-D8BA5703E431" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_realtime:9.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "B83B8BB6-404C-4133-863F-2EA56F578EF9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_realtime:9.1.2.1:*:*:*:*:*:*:*", "matchCriteriaId": "FAB2F429-3FDC-4417-B87D-B18F14BF3E59" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_realtime:9.5.0:*:*:*:*:*:*:*", "matchCriteriaId": "F387F0AF-A9A2-4917-8629-C825A7245C31" } ] } ] }, { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_for_websphere_software:8.5.0:*:*:*:*:*:*:*", "matchCriteriaId": "5AE76F94-2D79-461A-9AE3-DF3B6BA298E4" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_for_websphere_software:8.5.1:*:*:*:*:*:*:*", "matchCriteriaId": "EAF9DB3F-44B9-4913-831A-3CC090D526B3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_for_websphere_software:8.5.1.0:*:*:*:*:*:*:*", "matchCriteriaId": "C271F9B6-C2FC-44F1-A11A-1FE7E0D77B60" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_for_websphere_software:8.5.5:*:*:*:*:*:*:*", "matchCriteriaId": "E9388CA4-5788-47D2-9FDF-742E1FCD1DCF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_for_websphere_software:8.5.5.2:*:*:*:*:*:*:*", "matchCriteriaId": "927442F7-1308-4885-B6D8-74262D5B5734" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_for_websphere_software:8.5.5.3:*:*:*:*:*:*:*", "matchCriteriaId": "A13B7E9B-47E9-4CFF-906B-47BA7B9BCD83" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_for_websphere_software:8.5.5.4:*:*:*:*:*:*:*", "matchCriteriaId": "66A57DC1-5908-4901-8544-8959F2550E32" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_for_websphere_software:9.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "3A5524A4-A3A7-48E6-8D88-478A2475EAE3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_for_websphere_software:9.0.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "48CD42F7-D3BE-4B30-913B-B9D3E30C38C4" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_for_websphere_software:9.1.0:*:*:*:*:*:*:*", "matchCriteriaId": "371E9242-F789-4BBB-AF9B-DD2CBB5C3890" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_for_websphere_software:9.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "68D84B4C-956A-4274-A467-A3A30E19D092" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_for_websphere_software:9.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "E8448264-4C92-4C44-823C-CC1B20853611" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_for_websphere_software:9.1.2.1:*:*:*:*:*:*:*", "matchCriteriaId": "06FC859E-4B40-4A95-AED7-0D4A792EA222" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_for_websphere_software:9.5.0:*:*:*:*:*:*:*", "matchCriteriaId": "8D388EEE-3BBB-40CB-82E1-E3C150A76BF6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect_for_websphere_software\\':8.5.5.1:*:*:*:*:*:*:*", "matchCriteriaId": "1B5BF9ED-7DB5-4D57-92EF-6825C50837F7" } ] } ] }, { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect:8.5.0:*:*:*:*:*:*:*", "matchCriteriaId": "8D5F2F18-6946-459D-9789-F32CBD783D74" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect:8.5.1:*:*:*:*:*:*:*", "matchCriteriaId": "D3D9678E-FBB7-4C88-BF3C-6A9DCD3AF26C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect:8.5.1.0:*:*:*:*:*:*:*", "matchCriteriaId": "2AEEC4F8-D65B-4233-9F49-BCA6D20C825B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect:8.5.5:*:*:*:*:*:*:*", "matchCriteriaId": "E0121E14-22DC-4DBF-B197-E01998937BBD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect:8.5.5.1:*:*:*:*:*:*:*", "matchCriteriaId": "C6E3D169-14AA-4A10-B2EF-9E53A0F91A72" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect:8.5.5.2:*:*:*:*:*:*:*", "matchCriteriaId": "41AB9C7A-B83B-40A0-974C-C6662C910793" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect:8.5.5.3:*:*:*:*:*:*:*", "matchCriteriaId": "39AEE008-9216-4757-BE37-57E07071F191" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect:8.5.5.4:*:*:*:*:*:*:*", "matchCriteriaId": "12BF54A5-3D0E-4219-A399-4F6669D755C9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect:9.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "3366D021-ACB1-4C0B-A48D-CF499486612A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect:9.0.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "570FB15D-E709-4BEE-A6A9-68AE7F7DC77B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect:9.1.0:*:*:*:*:*:*:*", "matchCriteriaId": "949A79A8-332D-4601-9D54-9663EDE77BB4" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect:9.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "BE81BAC8-C441-4DAE-97D9-E3050D113524" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect:9.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "DF4EAAB5-F4C1-4B5B-90D7-F369D3F0455B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect:9.1.2.1:*:*:*:*:*:*:*", "matchCriteriaId": "7DCD8E9F-0B9C-480B-83EC-C6E7EAAA223A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:rational_software_architect:9.5.0:*:*:*:*:*:*:*", "matchCriteriaId": "7E8F963E-1892-4AD4-87A9-82D7E58080C3" } ] } ] } ], "references": [ { "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21972909", "source": "psirt@us.ibm.com", "tags": [ "Vendor Advisory" ] } ] }