First published: Wed Jan 28 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3) dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in the IBM Dojo Toolkit, as used in IBM Social Media Analytics 1.3 before IF11 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Social Media Analytics | <=1.3.0.0 | |
Ibm Financial Transaction Manager | =2.0.0.0 | |
Ibm Financial Transaction Manager | =2.0.0.1 | |
Ibm Financial Transaction Manager | =2.0.0.2 | |
Ibm Financial Transaction Manager | =2.0.0.3 | |
Ibm Financial Transaction Manager | =2.1.0.0 | |
Ibm Financial Transaction Manager | =2.1.0.1 | |
Ibm Financial Transaction Manager | =2.1.0.2 | |
Ibm Financial Transaction Manager | =2.1.1.0 | |
Ibm Financial Transaction Manager | =2.1.1.1 | |
Ibm Financial Transaction Manager | =3.0.0.0 | |
Ibm Financial Transaction Manager For Check Services | =2.1.1.8 | |
Ibm Financial Transaction Manager For Corporate Payment Services | =2.1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8917 has a severity rating that indicates it can lead to cross-site scripting (XSS) attacks.
To remediate CVE-2014-8917, it is recommended to update to a version of the affected IBM products where the vulnerabilities have been patched.
CVE-2014-8917 impacts various versions of IBM Social Media Analytics and IBM Financial Transaction Manager.
The risks of CVE-2014-8917 include unauthorized access and manipulation of web applications through XSS vulnerabilities.
CVE-2014-8917 involves vulnerabilities in multiple Flash components, specifically uploader.swf and fileupload.swf among others.