CVE-2015-0109: XSS
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.8, and Maximo Asset Management 7.1 through 7.1.1.8 and 7.2 for Tivoli IT Asset Management for IT and certain other products, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-0104, CVE-2015-0107, and CVE-2015-0108.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0109?
CVE-2015-0109 is rated as a medium severity vulnerability due to the potential for remote authenticated users to inject web scripts or HTML.
How do I fix CVE-2015-0109?
To fix CVE-2015-0109, upgrade to the latest version of IBM Maximo Asset Management or apply any recommended patches provided by IBM.
What are the affected versions by CVE-2015-0109?
CVE-2015-0109 affects IBM Maximo Asset Management versions 7.1 through 7.1.1.8 and 7.2, along with certain Tivoli IT Asset Management products.
Who is vulnerable to CVE-2015-0109?
Remote authenticated users of IBM Maximo Asset Management and Tivoli IT Asset Management products are vulnerable to CVE-2015-0109.
What kind of attacks can CVE-2015-0109 lead to?
CVE-2015-0109 can lead to cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary scripts into web pages viewed by other users.