CVE-2009-2316: XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote attackers to inject arbitrary web script or HTML by entering an unspecified URL in (1) the self-service UI interface or (2) the console interface. NOTE: it was later reported that 4.6.0 is also affected by the first vector.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2316?
CVE-2009-2316 is considered a high severity vulnerability due to its potential for allowing remote attackers to execute malicious scripts.
How do I fix CVE-2009-2316?
To fix CVE-2009-2316, upgrade IBM Tivoli Identity Manager to the latest version that addresses this vulnerability.
What systems are affected by CVE-2009-2316?
CVE-2009-2316 affects IBM Tivoli Identity Manager version 5.0 and may also impact version 4.6.0.
Can CVE-2009-2316 be exploited remotely?
Yes, CVE-2009-2316 can be exploited remotely, allowing attackers to inject arbitrary web scripts.
What type of vulnerability is CVE-2009-2316?
CVE-2009-2316 is classified as a cross-site scripting (XSS) vulnerability.