CVE-2010-4120: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the TAM console in IBM Tivoli Access Manager for e-business 6.1.0 before 6.1.0-TIV-TAM-FP0006 allow remote attackers to inject arbitrary web script or HTML via (1) the parm1 parameter to ivt/ivtserver, or the method parameter to (2) acl, (3) domain, (4) group, (5) gso, (6) gsogroup, (7) os, (8) pop, (9) rule, (10) user, or (11) webseal in ibm/wpm/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4120?
CVE-2010-4120 is classified as a medium severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2010-4120?
To fix CVE-2010-4120, upgrade IBM Tivoli Access Manager for e-business to version 6.1.0-TIV-TAM-FP0006 or later.
What types of attacks can CVE-2010-4120 facilitate?
CVE-2010-4120 can facilitate cross-site scripting attacks, allowing attackers to inject malicious scripts into web pages.
Which versions of IBM Tivoli Access Manager for e-business are affected by CVE-2010-4120?
CVE-2010-4120 affects IBM Tivoli Access Manager for e-business version 6.1.0 prior to 6.1.0-TIV-TAM-FP0006 and 6.1.1.
Can CVE-2010-4120 be exploited without authentication?
Yes, CVE-2010-4120 can be exploited by remote attackers without requiring authentication.