First published: Wed Feb 20 2013(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to a uisessionid.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | =7.5.0.0 | |
IBM Maximo Asset Management Essentials | =7.5.0.0 | |
IBM Control Desk | =7.5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0457 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2013-0457, users should apply the latest security patches provided by IBM for Maximo Asset Management and SmartCloud Control Desk.
CVE-2013-0457 affects remote authenticated users of IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5.
CVE-2013-0457 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts or HTML.
CVE-2013-0457 cannot be exploited by unauthenticated users, as it requires authentication to inject scripts.