First published: Tue Mar 13 2012(Updated: )
Cross-site scripting (XSS) vulnerability in imicon.jsp in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote attackers to inject arbitrary web script or HTML via the controlid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Maximo Asset Management Essentials | =6.2 | |
IBM Maximo Asset Management | =7.5 | |
Ibm Maximo Asset Management Essentials | =7.5 | |
IBM Maximo Asset Management | =7.1 | |
IBM Maximo Asset Management | =6.2 | |
Ibm Maximo Asset Management Essentials | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1395 has a moderate severity level due to the potential for cross-site scripting attacks.
To fix CVE-2011-1395, ensure you apply the latest security patches provided by IBM for the affected versions of Maximo Asset Management.
CVE-2011-1395 affects IBM Maximo Asset Management and Asset Management Essentials versions 6.2, 7.1, and 7.5.
CVE-2011-1395 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Remote attackers can exploit CVE-2011-1395 to potentially compromise affected IBM Maximo systems.