CVE-2014-0638

Cross-site scripting (XSS) vulnerability in RSA Adaptive Authentication (On-Premise) 6.x and 7.x before 7.1 SP0 P2 allows remote attackers to inject arbitrary web script or HTML via vectors involving FRAME elements, related to a "cross-frame scripting" issue.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
dellCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
VendorProductVersion
emcrsa_adaptive_authentication_on-premise
6.0
emcrsa_adaptive_authentication_on-premise
6.0.2.1
emcrsa_adaptive_authentication_on-premise
6.0.2.1:sp1_patch2
emcrsa_adaptive_authentication_on-premise
6.0.2.1:sp1_patch3
emcrsa_adaptive_authentication_on-premise
6.0.2.1:sp2
emcrsa_adaptive_authentication_on-premise
6.0.2.1:sp2_patch1
emcrsa_adaptive_authentication_on-premise
6.0.2.1:sp3
emcrsa_adaptive_authentication_on-premise
6.0.2.1:sp3_p3
emcrsa_adaptive_authentication_on-premise
7.0
emcrsa_adaptive_authentication_on-premise
7.1
𝑥
= Vulnerable software versions