Show plain JSON{"id": "CVE-2012-5949", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}]}, "published": "2013-04-23T11:47:35.820", "references": [{"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21628851", "tags": ["Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21628852", "tags": ["Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/80629", "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21628851", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21628852", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/80629", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject content, and conduct phishing attacks, via vectors involving (1) the html/en/default/ directory, (2) birt/frameset, (3) WebProcess.srv, (4) sqa/html/en/default/reportTemplate/reportTemplateOrderCols.jsp, or (5) a/html/en/default/om2/omObjectFinder.jsp."}, {"lang": "es", "value": "Multiples vulnerabilidades de ejecuci\u00f3n de secuencias de comandos en sitios cruzados (XSS) en IBM TRIRIGA Application Platform v2.x y v3.x antes de v3.3, y v8, que permiten a atacantes remotos inyectar contenido, y llevar a cabo ataques de phishing, a trav\u00e9s de vectores relacionados con (1) el html/es/default/, (2) birt/frameset, (3) WebProcess.srv, (4) sqa/html/es/default/reportTemplate/reportTemplateOrderCols.jsp, o (5) a/html/en/default/om2/omObjectFinder.jsp."}], "lastModified": "2025-04-11T00:51:21.963", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:tririga_application_platform:2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B3ECDCA8-28FA-4A03-A51E-B8335B6AE9A1"}, {"criteria": "cpe:2.3:a:ibm:tririga_application_platform:2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2DA2E984-DD46-4F16-849A-C6E488402E80"}, {"criteria": "cpe:2.3:a:ibm:tririga_application_platform:2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8DF2E581-2EA5-41E2-9A13-CEC92AF70CDD"}, {"criteria": "cpe:2.3:a:ibm:tririga_application_platform:2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AE66AD36-46F2-48A4-A9BB-C5E291C45884"}, {"criteria": "cpe:2.3:a:ibm:tririga_application_platform:3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "76EEEE27-65F4-4CF0-BE6E-1B95B63A913D"}, {"criteria": "cpe:2.3:a:ibm:tririga_application_platform:3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B4EB23AD-8FCF-4E82-8B8D-183E13AC7BB8"}, {"criteria": "cpe:2.3:a:ibm:tririga_application_platform:3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "63B37387-4218-4B92-BD39-4EA5E849DB51"}, {"criteria": "cpe:2.3:a:ibm:tririga_application_platform:3.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "46D0A920-F5D2-4FB7-8EF1-E892B27F3158"}, {"criteria": "cpe:2.3:a:ibm:tririga_application_platform:8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B7D9417A-9A12-4D30-8204-ADECFB901142"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@us.ibm.com"}