CVE-2012-0740: XSS
Cross-site scripting (XSS) vulnerability in the Web Admin Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.22 and 6.3 before 6.3.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What versions of IBM Tivoli Directory Server are affected by CVE-2012-0740?
CVE-2012-0740 affects IBM Tivoli Directory Server versions 6.2 before 6.2.0.22 and 6.3 before 6.3.0.11.
What type of vulnerability is identified by CVE-2012-0740?
CVE-2012-0740 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
How do I mitigate CVE-2012-0740?
To mitigate CVE-2012-0740, it is recommended to update IBM Tivoli Directory Server to versions 6.2.0.22 or 6.3.0.11 or later.
What impact does CVE-2012-0740 have on the affected systems?
CVE-2012-0740 can potentially allow an attacker to execute malicious scripts in the context of a user's web session.
Is there an official fix available for CVE-2012-0740?
Yes, fixing CVE-2012-0740 involves applying the official patches released by IBM for the affected versions.