CVE-2012-3316: XSS
Cross-site scripting (XSS) vulnerability in the Tivoli Process Automation Engine (TPAE) in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3316?
The severity of CVE-2012-3316 is classified as moderate due to the potential for cross-site scripting attacks.
How do I fix CVE-2012-3316?
To fix CVE-2012-3316, users should apply the latest security patches provided by IBM for the affected Maximo and Tivoli products.
Which versions are affected by CVE-2012-3316?
CVE-2012-3316 affects IBM Maximo Asset Management versions 6.2 through 7.5 and Tivoli Service Request Manager versions 7.1 and 7.2.
Can CVE-2012-3316 allow for user data compromise?
Yes, CVE-2012-3316 can lead to user data compromise through cross-site scripting, allowing attackers to execute scripts in the user's browser.
Is CVE-2012-3316 related to web applications?
Yes, CVE-2012-3316 is specifically related to web applications that utilize IBM's Tivoli Process Automation Engine.