CVE-2008-3161: XSS
Multiple cross-site scripting (XSS) vulnerabilities in jsp/common/system/debug.jsp in IBM Maximo 4.1 and 5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Accept, (2) Accept-Language, (3) UA-CPU, (4) Accept-Encoding, (5) User-Agent, or (6) Cookie HTTP header. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3161?
CVE-2008-3161 is considered a medium to high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2008-3161?
To address CVE-2008-3161, it is recommended to update IBM Maximo to a version that is not affected by this vulnerability.
What systems are affected by CVE-2008-3161?
CVE-2008-3161 affects IBM Maximo versions 4.1 and 5.2.
Can CVE-2008-3161 be exploited remotely?
Yes, CVE-2008-3161 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.
What types of HTTP headers are involved in the CVE-2008-3161 vulnerability?
CVE-2008-3161 involves several HTTP headers including Accept, Accept-Language, UA-CPU, Accept-Encoding, User-Agent, and Cookie.