First published: Wed Jun 20 2012(Updated: )
Cross-site scripting (XSS) vulnerability in deferredView.jsp in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security AppScan | =7.0 | |
IBM Security AppScan | =8.0 | |
IBM Security AppScan | =8.0.0.1 | |
IBM Security AppScan | =8.0.0.2 | |
IBM Security AppScan | =8.5 | |
IBM Security AppScan | =8.5.0.1 | |
IBM SPSS Data Collection | =6.0 | |
IBM SPSS Data Collection | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-2161 is classified as medium, due to its potential for exploitation through cross-site scripting.
To fix CVE-2012-2161, update the affected IBM Eclipse Help System to versions 8.6 or later.
CVE-2012-2161 affects IBM Security AppScan Source versions 7.x and 8.x prior to 8.6 and IBM SPSS Data Collection versions 6.0 and 6.0.1.
CVE-2012-2161 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts or HTML.
Yes, CVE-2012-2161 can be exploited remotely via crafted URLs.