CVE-2011-4819: XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allow remote attackers to inject arbitrary web script or HTML via the uisesionid parameter to (1) maximo.jsp or (2) the default URI under ui/.
Affected Software
Event History
Frequently Asked Questions
What are the consequences of CVE-2011-4819?
CVE-2011-4819 allows remote attackers to execute arbitrary web scripts or HTML, potentially compromising user sessions and data.
How do I fix CVE-2011-4819?
To remediate CVE-2011-4819, upgrade to the latest versions of IBM Maximo Asset Management or apply security patches provided by IBM.
Which versions of IBM Maximo are affected by CVE-2011-4819?
IBM Maximo Asset Management and Asset Management Essentials versions 6.2, 7.1, and 7.5 are affected by CVE-2011-4819.
Is there a workaround for CVE-2011-4819?
While a permanent fix is recommended, limiting access to the vulnerable URIs may serve as a temporary mitigation for CVE-2011-4819.
What is the risk level of CVE-2011-4819?
CVE-2011-4819 is considered a medium to high risk vulnerability due to its potential for cross-site scripting attacks.