CVE-2014-6096: XSS
Published Nov 18, 2014
·Updated
Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
4 affected components
IBM Security Identity Manager=6.0.0.0
IBM Security Identity Manager=6.0.0.1
IBM Security Identity Manager=6.0.0.2
IBM Security Identity Manager=6.0.0.3
Event History
Nov 18, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6096?
CVE-2014-6096 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-6096?
The recommended fix for CVE-2014-6096 is to update IBM Security Identity Manager to version 6.0.0.3 or later.
3
What versions of IBM Security Identity Manager are affected by CVE-2014-6096?
CVE-2014-6096 affects versions 6.0.0.0, 6.0.0.1, 6.0.0.2, and 6.0.0.3 before the IF14 update.
4
What type of vulnerability is CVE-2014-6096?
CVE-2014-6096 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts or HTML.
5
Who can exploit CVE-2014-6096?
CVE-2014-6096 can be exploited by remote attackers through the use of crafted URLs.