First published: Wed Mar 06 2013(Updated: )
Cross-site scripting (XSS) vulnerability in Welcome.do in the Data Management Portal Web User Interface in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Application Dependency Discovery Manager | =7.2.0.0 | |
IBM Tivoli Application Dependency Discovery Manager | =7.2.1 | |
IBM Tivoli Application Dependency Discovery Manager | =7.2.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5939 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To mitigate CVE-2012-5939, upgrade to IBM Tivoli Application Dependency Discovery Manager version 7.2.1.4 or later.
CVE-2012-5939 affects IBM Tivoli Application Dependency Discovery Manager versions 7.2.0.0, 7.2.1, and 7.2.1.3.
Yes, CVE-2012-5939 can be exploited remotely by authenticated users through crafted URLs.
CVE-2012-5939 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web script or HTML.