CVE-2014-0870: XSS
Multiple cross-site scripting (XSS) vulnerabilities in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to inject arbitrary web script or HTML via (1) the Message parameter to rcore6/main/showerror.jsp, (2) the ButtonsetClass parameter to rcore6/main/buttonset.jsp, (3) the MBName parameter to rcore6/frameset.jsp, (4) the Init parameter to algopds/rcore6/main/browse.jsp, or the (5) Name, (6) StoreName, or (7) STYLESHEET parameter to algopds/rcore6/main/ibrowseheader.jsp.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0870?
CVE-2014-0870 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2014-0870?
To fix CVE-2014-0870, upgrade IBM Algo Credit Limits to version 4.7.0.03 FP5 or later.
What types of attacks can be executed using CVE-2014-0870?
CVE-2014-0870 allows remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
Which versions of IBM Algo Credit Limits are affected by CVE-2014-0870?
CVE-2014-0870 affects IBM Algo Credit Limits versions 4.5.0 to 4.7.0 prior to version 4.7.0.03 FP5.
What components of IBM Algorithmics are impacted by CVE-2014-0870?
CVE-2014-0870 primarily impacts the RICOS component of IBM Algorithmics, allowing for XSS vulnerabilities.