First published: Thu May 01 2014(Updated: )
Cross-site scripting (XSS) vulnerability in webtop/eventviewer/eventViewer.jsp in the Web GUI in IBM Netcool/OMNIbus 7.4.0 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-0942.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Tivoli Netcool\/omnibus | =7.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0941 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2014-0941, apply the latest fixes or patches provided by IBM for Tivoli Netcool/OMNIbus version 7.4.0.
CVE-2014-0941 affects remote authenticated users of IBM Netcool/OMNIbus version 7.4.0 prior to Fix Pack 2.
CVE-2014-0941 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts or HTML.
No, CVE-2014-0941 requires remote authenticated access to exploit the vulnerability.