First published: Thu Mar 22 2012(Updated: )
Cross-site scripting (XSS) vulnerability in checkQKMProg.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quantum Scalar I500 Firmware | <=i7.0.2 | |
Quantum Scalar I500 Firmware | =i2 | |
Quantum Scalar I500 Firmware | =i3 | |
Quantum Scalar I500 Firmware | =i3.1 | |
Quantum Scalar I500 Firmware | =i4 | |
Quantum Scalar I500 Firmware | =i5 | |
Quantum Scalar I500 Firmware | =i5.1 | |
Quantum Scalar I500 Firmware | =i6 | |
Quantum Scalar I500 Firmware | =i6.1 | |
Quantum Scalar I500 Firmware | =i7 | |
Quantum Scalar I500 Firmware | =i7.0.1 | |
Quantum Scalar I500 Firmware | =sp4 | |
Quantum Scalar I500 Firmware | =sp4.2 | |
Quantum Scalar i500 | =5u | |
Quantum Scalar i500 | =14u | |
Quantum Scalar i500 | =23u | |
Dell Powervault ML6000 Firmware | =585g.gs003 | |
Dell Powervault ML6000 | =32u | |
Dell Powervault ML6000 | =41u | |
Dell Powervault ML6010 | =5u | |
Dell PowerVault ML6020 | =14u | |
Dell Powervault Ml6030 | =23u |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1842 is classified as a medium severity vulnerability due to its impact on web security.
To fix CVE-2012-1842, you need to upgrade the firmware of the Quantum Scalar i500 tape library to version i7.0.3 or later.
CVE-2012-1842 affects Quantum Scalar i500 tape libraries with firmware versions prior to i7.0.3 and Dell ML6000 tape libraries before firmware A20-00.
Yes, CVE-2012-1842 allows remote attackers to inject arbitrary web scripts or HTML through vulnerable interfaces.
CVE-2012-1842 can facilitate cross-site scripting (XSS) attacks, potentially allowing attackers to steal cookies or session tokens.