CVE-2014-0893: XSS
Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM Maximo Asset Management 7.5.x before 7.5.0.5 IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0893?
CVE-2014-0893 has a medium severity rating that indicates it can lead to significant vulnerabilities if exploited.
How do I fix CVE-2014-0893?
To fix CVE-2014-0893, it is recommended to apply the latest patches provided by IBM for the affected versions.
Which versions are affected by CVE-2014-0893?
CVE-2014-0893 affects IBM Maximo Asset Management versions 7.5.0.0 to 7.5.0.4 and SmartCloud Control Desk versions 7.x before 7.5.0.3.
Can remote attackers exploit CVE-2014-0893?
Yes, CVE-2014-0893 allows remote authenticated users to inject arbitrary web scripts or HTML, potentially affecting application integrity.
What type of vulnerability is CVE-2014-0893?
CVE-2014-0893 is a cross-site scripting (XSS) vulnerability that can be exploited by injecting malicious scripts into web pages.