First published: Tue Aug 26 2014(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Emptoris Spend Analysis | =9.5.0.0 | |
IBM Emptoris Spend Analysis | =9.5.0.1 | |
IBM Emptoris Spend Analysis | =9.5.0.2 | |
IBM Emptoris Spend Analysis | =9.5.0.3 | |
IBM Emptoris Spend Analysis | =10.0.1.0 | |
IBM Emptoris Spend Analysis | =10.0.1.1 | |
IBM Emptoris Spend Analysis | =10.0.1.2 | |
IBM Emptoris Spend Analysis | =10.0.2.0 | |
IBM Emptoris Spend Analysis | =10.0.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3035 is classified as a moderate severity vulnerability that allows for cross-site scripting.
To fix CVE-2014-3035, upgrade IBM Emptoris Spend Analysis to the latest version providing the security patch.
CVE-2014-3035 affects users of IBM Emptoris Spend Analysis versions prior to 9.5.0.4, 10.0.1.3, and 10.0.2.4.
CVE-2014-3035 allows attackers to inject arbitrary web scripts or HTML, potentially leading to data theft or session hijacking.
Yes, CVE-2014-3035 requires remote authenticated users to exploit the cross-site scripting vulnerability.