Overview
Serena Dimensions CM 12.2 Build 7.199.0 web client and possibly earlier versions contains multiple cross-site scripting vulnerabilities.
Description
| Serena Dimensions CM 12.2 Build 7.199.0 web client and possibly earlier versions contains multiple cross-site scripting vulnerabilities. CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') - CVE-2014-0335 | 
Impact
| A remote unauthenticated attacker may be able to execute arbitrary script in the context of the end-user's browser session. | 
Solution
| Apply an update 
 | 
| Restrict access | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P | 
| Temporal | 5.5 | E:POC/RL:U/RC:UC | 
| Environmental | 1.4 | CDP:ND/TD:L/CR:ND/IR:ND/AR:ND | 
References
Acknowledgements
Thanks to Ken Cijsouw for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
| CVE IDs: | CVE-2014-0335, CVE-2014-0336 | 
| Date Public: | 2014-03-07 | 
| Date First Published: | 2014-03-05 | 
| Date Last Updated: | 2015-09-17 14:15 UTC | 
| Document Revision: | 14 |