First published: Wed Nov 12 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the web-based interface in IBM Metrica Service Assurance Framework allow remote authenticated users to inject arbitrary web script or HTML via (1) the elementid parameter in a generatedreportresults action to the ReportTree program, (2) the jnlpname parameter to the Launch program, or (3) the :tasklabel parameter to the ReportRequest program, related to the name of a report.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Metrica Service Assurance Framework |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.