{"api_version":"1","generated_at":"2026-07-23T11:52:59+00:00","cve":"CVE-2007-4348","urls":{"html":"https://cve.report/CVE-2007-4348","api":"https://cve.report/api/cve/CVE-2007-4348.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4348","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4348"},"summary":{"title":"CVE-2007-4348","description":"Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log entries in a dsmerror.log file that is accessible through a certain web interface.","state":"PUBLISHED","assigner":"flexera","published_at":"2007-10-30 19:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/27013","name":"http://secunia.com/advisories/27013","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM Tivoli Storage Manager Client CAD Service Script Insertion - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/secunia_research/2007-75/advisory","name":"http://secunia.com/secunia_research/2007-75/advisory","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM Tivoli Storage Manager Client CAD Service Script Insertion - Secunia Research - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/3635","name":"http://www.vupen.com/english/advisories/2007/3635","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1018868","name":"http://www.securitytracker.com/id?1018868","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Tivoli Storage Manager Input Validation Hole in CAD Service Permits Script Injection Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/26221","name":"http://www.securityfocus.com/bid/26221","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Tivoli Storage Manager Client CAD Service HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38125","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38125","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4348","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4348","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4348","vulnerable":"1","versionEndIncluding":"5.3.5.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager_client","cpe6":"*","cpe7":"*","cpe8":"windows","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4348","vulnerable":"1","versionEndIncluding":"5.4.1.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager_client","cpe6":"*","cpe7":"*","cpe8":"windows","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:53:55.825Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2007-3635","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3635"},{"name":"ibm-tsm-cad-xss(38125)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38125"},{"name":"26221","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26221"},{"name":"27013","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27013"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2007-75/advisory"},{"name":"1018868","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018868"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-10-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log entries in a dsmerror.log file that is accessible through a certain web interface."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","shortName":"flexera"},"references":[{"name":"ADV-2007-3635","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3635"},{"name":"ibm-tsm-cad-xss(38125)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38125"},{"name":"26221","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26221"},{"name":"27013","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27013"},{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2007-75/advisory"},{"name":"1018868","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018868"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"PSIRT-CNA@flexerasoftware.com","ID":"CVE-2007-4348","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log entries in a dsmerror.log file that is accessible through a certain web interface."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2007-3635","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3635"},{"name":"ibm-tsm-cad-xss(38125)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38125"},{"name":"26221","refsource":"BID","url":"http://www.securityfocus.com/bid/26221"},{"name":"27013","refsource":"SECUNIA","url":"http://secunia.com/advisories/27013"},{"name":"http://secunia.com/secunia_research/2007-75/advisory","refsource":"MISC","url":"http://secunia.com/secunia_research/2007-75/advisory"},{"name":"1018868","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018868"}]}}}},"cveMetadata":{"assignerOrgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","assignerShortName":"flexera","cveId":"CVE-2007-4348","datePublished":"2007-10-30T19:00:00.000Z","dateReserved":"2007-08-14T00:00:00.000Z","dateUpdated":"2024-08-07T14:53:55.825Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-10-30 19:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager_client:*:*:windows:*:*:*:*:*","versionEndIncluding":"5.3.5.3","matchCriteriaId":"E4DEFF48-95FF-4D54-AF04-939811F8F45B"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager_client:*:*:windows:*:*:*:*:*","versionEndIncluding":"5.4.1.2","matchCriteriaId":"55907781-26CA-4E19-BC19-D30ADE1FAEC4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4348","Ordinal":"1","Title":"CVE-2007-4348","CVE":"CVE-2007-4348","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4348","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log entries in a dsmerror.log file that is accessible through a certain web interface.","Type":"Description","Title":"CVE-2007-4348"},{"CveYear":"2007","CveId":"4348","Ordinal":"2","NoteData":"2007-10-30","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4348","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}