| Publication Date: |
2020-09-08 |
| Last Update: |
2020-09-08 |
| Current Version: |
V1.0 |
| CVSS v3.1 Base Score: |
8.1 |
| Affected Product and Versions |
Remediation |
|
Polarion Subversion Webclient:
All versions
|
The tool is considered shareware, distributed “as is” and there will not be a fix as it is no longer supported
|
- Do not open unknown links while working on Polarion Subversion webclient
| CVSS v3.1 Base Score |
6.1 |
| CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:P/RL:U/RC:C |
| CWE: |
CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) |
| CVSS v3.1 Base Score |
8.1 |
| CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:P/RL:U/RC:C |
| CWE: |
CWE-352: Cross-Site Request Forgery (CSRF) |
-
Li Yifan from
Bolean Technology LTD.
for coordinated disclosure
https://www.siemens.com/cert/advisories