First published: Thu May 01 2014(Updated: )
Cross-site scripting (XSS) vulnerability in webtop/eventviewer/eventViewer.jsp in the Web GUI in IBM Netcool/OMNIbus 7.4.0 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-0941.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Tivoli Netcool\/omnibus | =7.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0942 is classified as a medium-severity vulnerability due to the risk of XSS attacks.
To fix CVE-2014-0942, upgrade IBM Netcool/OMNIbus to version 7.4.0 FP2 or later.
CVE-2014-0942 affects users of IBM Netcool/OMNIbus version 7.4.0 prior to Fix Pack 2.
CVE-2014-0942 is a cross-site scripting (XSS) vulnerability that allows unauthorized script injection.
Yes, remote authenticated users can exploit CVE-2014-0942 by injecting malicious scripts via crafted URLs.