CVE-2015-0108: XSS
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.8, and Maximo Asset Management 7.1 through 7.1.1.8 and 7.2 for Tivoli IT Asset Management for IT and certain other products, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-0104, CVE-2015-0107, and CVE-2015-0109.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0108?
CVE-2015-0108 has a medium severity rating, indicating potential for exploitation in certain scenarios.
How do I fix CVE-2015-0108?
To fix CVE-2015-0108, update your IBM Maximo Asset Management or related products to the latest version that addresses this vulnerability.
Who is affected by CVE-2015-0108?
CVE-2015-0108 affects IBM Maximo Asset Management versions 7.1 through 7.1.1.8, and certain other IBM Tivoli products.
What type of vulnerability is CVE-2015-0108?
CVE-2015-0108 is a cross-site scripting (XSS) vulnerability that allows users to inject arbitrary web script or HTML.
Can CVE-2015-0108 be exploited remotely?
Yes, CVE-2015-0108 can potentially be exploited by remote authenticated users.