CVE-2014-0945
Summary
| CVE | CVE-2014-0945 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-05-09 10:50:00 UTC |
| Updated | 2017-08-29 01:34:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Operational Decision Manager | 7.5 | All | All | All |
| Application | Ibm | Operational Decision Manager | 8.0 | All | All | All |
| Application | Ibm | Operational Decision Manager | 8.5 | All | All | All |
| Application | Ibm | Operational Decision Manager | 7.5 | All | All | All |
| Application | Ibm | Operational Decision Manager | 8.0 | All | All | All |
| Application | Ibm | Operational Decision Manager | 8.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: IBM Operational Decision Manager : CVE-2014-0944, CVE-2014-0945, CVE-2014-0946 | CONFIRM | www-01.ibm.com | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.