Cross-site scripting (XSS) vulnerability in IBM Document Connect for Application Support Facility (aka DC4ASF) before 1.0.0.1218 in Application Support Facility (ASF) 3.4 for z/OS on Windows, Linux, and AIX allows remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.
2013-04-27T03:16:46.863
2025-04-11T00:51:21.963
Deferred
CVSSv2: 2.3 (LOW)
AV:A/AC:M/Au:S/C:N/I:P/A:N
4.4
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | application_support_facility | 3.4.0 | Yes |
Application | ibm | application_support_facility | 3.4.0 | Yes |
Application | ibm | application_support_facility | 3.4.0 | Yes |
Application | ibm | application_support_facility | 3.4.0 | Yes |
Application | ibm | document_connect_for_application_support_facility | ≤ 1.0.0.1204 | Yes |