First published: Mon May 26 2014(Updated: )
Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM Maximo Asset Management 7.5.x before 7.5.0.5 IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | =7.5.0.0 | |
IBM Maximo Asset Management | =7.5.0.1 | |
IBM Maximo Asset Management | =7.5.0.2 | |
IBM Maximo Asset Management | =7.5.0.3 | |
IBM Maximo Asset Management | =7.5.0.4 | |
IBM Maximo Asset Management | =7.5.0.5 | |
IBM Control Desk | =7.0 | |
IBM Control Desk | =7.5 | |
IBM Control Desk | =7.5.0.0 | |
IBM Control Desk | =7.5.0.1 | |
IBM Control Desk | =7.5.0.2 | |
IBM Control Desk | =7.5.0.3 | |
IBM Control Desk | =7.5.0.5 | |
IBM Control Desk | =7.5.1.0 | |
IBM Control Desk | =7.5.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0893 has a medium severity rating that indicates it can lead to significant vulnerabilities if exploited.
To fix CVE-2014-0893, it is recommended to apply the latest patches provided by IBM for the affected versions.
CVE-2014-0893 affects IBM Maximo Asset Management versions 7.5.0.0 to 7.5.0.4 and SmartCloud Control Desk versions 7.x before 7.5.0.3.
Yes, CVE-2014-0893 allows remote authenticated users to inject arbitrary web scripts or HTML, potentially affecting application integrity.
CVE-2014-0893 is a cross-site scripting (XSS) vulnerability that can be exploited by injecting malicious scripts into web pages.