CVE-2011-1396: XSS
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote attackers to inject arbitrary web script or HTML via the reportType parameter to an unspecified component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1396?
CVE-2011-1396 is classified as a medium severity vulnerability due to its XSS implications.
How do I fix CVE-2011-1396?
To fix CVE-2011-1396, upgrade to the latest version of IBM Maximo Asset Management or apply the relevant patches provided by IBM.
What are the potential impacts of CVE-2011-1396?
The potential impacts of CVE-2011-1396 include unauthorized access to user accounts and the ability to execute malicious scripts in the context of a user's session.
Which IBM Maximo versions are affected by CVE-2011-1396?
CVE-2011-1396 affects IBM Maximo Asset Management versions 6.2, 7.1, and 7.5, as well as the Asset Management Essentials versions.
Who can exploit CVE-2011-1396?
CVE-2011-1396 can be exploited by remote attackers who can manipulate the reportType parameter in web requests.