First published: Tue Mar 13 2012(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote attackers to inject arbitrary web script or HTML via the reportType parameter to an unspecified component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Maximo Asset Management Essentials | =6.2 | |
IBM Maximo Asset Management | =7.5 | |
Ibm Maximo Asset Management Essentials | =7.5 | |
IBM Maximo Asset Management | =7.1 | |
IBM Maximo Asset Management | =6.2 | |
Ibm Maximo Asset Management Essentials | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1396 is classified as a medium severity vulnerability due to its XSS implications.
To fix CVE-2011-1396, upgrade to the latest version of IBM Maximo Asset Management or apply the relevant patches provided by IBM.
The potential impacts of CVE-2011-1396 include unauthorized access to user accounts and the ability to execute malicious scripts in the context of a user's session.
CVE-2011-1396 affects IBM Maximo Asset Management versions 6.2, 7.1, and 7.5, as well as the Asset Management Essentials versions.
CVE-2011-1396 can be exploited by remote attackers who can manipulate the reportType parameter in web requests.