CVE-2014-8917: XSS
Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3) dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in the IBM Dojo Toolkit, as used in IBM Social Media Analytics 1.3 before IF11 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8917?
CVE-2014-8917 has a severity rating that indicates it can lead to cross-site scripting (XSS) attacks.
How do I fix CVE-2014-8917?
To remediate CVE-2014-8917, it is recommended to update to a version of the affected IBM products where the vulnerabilities have been patched.
What systems are affected by CVE-2014-8917?
CVE-2014-8917 impacts various versions of IBM Social Media Analytics and IBM Financial Transaction Manager.
What are the risks associated with CVE-2014-8917?
The risks of CVE-2014-8917 include unauthorized access and manipulation of web applications through XSS vulnerabilities.
What components are involved in CVE-2014-8917?
CVE-2014-8917 involves vulnerabilities in multiple Flash components, specifically uploader.swf and fileupload.swf among others.