{"api_version":"1","generated_at":"2026-07-23T05:31:01+00:00","cve":"CVE-2014-8917","urls":{"html":"https://cve.report/CVE-2014-8917","api":"https://cve.report/api/cve/CVE-2014-8917.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-8917","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-8917"},"summary":{"title":"CVE-2014-8917","description":"Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3) dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in the IBM Dojo Toolkit, as used in IBM Social Media Analytics 1.3 before IF11 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.","state":"PUBLISHED","assigner":"ibm","published_at":"2015-01-28 22:59:00","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/62590","name":"http://secunia.com/advisories/62590","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA62590 - IBM Social Media Analytics Multiple Cross-Site Scripting Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21696013","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21696013","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM Security Bulletin: IBM Financial Transaction Manager affected by IBM Dojo Toolkit is vulnerable to cross-site scripting (CVE-2014-8917) - United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/62837","name":"http://secunia.com/advisories/62837","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About Secunia Research | Flexera","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.securitytracker.com/id/1032376","name":"http://www.securitytracker.com/id/1032376","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Domino Buffer Overflows Let Remote Users Execute Arbitrary Code and Input Validation Flaw Permits Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/72903","name":"http://www.securityfocus.com/bid/72903","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Dojo Toolkit CVE-2014-8917 Multiple Cross Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21694693","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21694693","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IBM A Security vulnerability in the IBM Dojo Toolkit affects IBM Social Media Analytics (CVE-2014-8917) - United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99303","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99303","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-8917","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-8917","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"8917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"financial_transaction_manager","cpe6":"2.0.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"financial_transaction_manager","cpe6":"2.0.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"financial_transaction_manager","cpe6":"2.0.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"financial_transaction_manager","cpe6":"2.0.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"financial_transaction_manager","cpe6":"2.1.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"financial_transaction_manager","cpe6":"2.1.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"financial_transaction_manager","cpe6":"2.1.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"financial_transaction_manager","cpe6":"2.1.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"financial_transaction_manager","cpe6":"2.1.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"financial_transaction_manager","cpe6":"3.0.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"financial_transaction_manager_for_check_services","cpe6":"2.1.1.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"financial_transaction_manager_for_corporate_payment_services","cpe6":"2.1.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8917","vulnerable":"1","versionEndIncluding":"1.3.0.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"social_media_analytics","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T13:33:12.610Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"62590","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/62590"},{"name":"ibm-dojo-cve20148917-xss(99303)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99303"},{"name":"62837","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/62837"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21696013"},{"name":"1032376","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1032376"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21694693"},{"name":"72903","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/72903"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-01-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3) dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in the IBM Dojo Toolkit, as used in IBM Social Media Analytics 1.3 before IF11 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-07T15:57:01.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"name":"62590","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/62590"},{"name":"ibm-dojo-cve20148917-xss(99303)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99303"},{"name":"62837","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/62837"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21696013"},{"name":"1032376","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1032376"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21694693"},{"name":"72903","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/72903"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2014-8917","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3) dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in the IBM Dojo Toolkit, as used in IBM Social Media Analytics 1.3 before IF11 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"62590","refsource":"SECUNIA","url":"http://secunia.com/advisories/62590"},{"name":"ibm-dojo-cve20148917-xss(99303)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99303"},{"name":"62837","refsource":"SECUNIA","url":"http://secunia.com/advisories/62837"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21696013","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21696013"},{"name":"1032376","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1032376"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21694693","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21694693"},{"name":"72903","refsource":"BID","url":"http://www.securityfocus.com/bid/72903"}]}}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2014-8917","datePublished":"2015-01-28T22:00:00.000Z","dateReserved":"2014-11-14T00:00:00.000Z","dateUpdated":"2024-08-06T13:33:12.610Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-01-28 22:59:00","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:social_media_analytics:*:*:*:*:*:*:*:*","versionEndIncluding":"1.3.0.0","matchCriteriaId":"0CE0E0AB-2001-43EC-8567-F43FC86E891E"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:financial_transaction_manager:2.0.0.0:*:*:*:*:*:*:*","matchCriteriaId":"FE1B7481-D995-46AA-9761-481625A8E6CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:financial_transaction_manager:2.0.0.1:*:*:*:*:*:*:*","matchCriteriaId":"83DE18A8-618E-458A-B540-1691D822997E"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:financial_transaction_manager:2.0.0.2:*:*:*:*:*:*:*","matchCriteriaId":"1273B643-91DC-48D7-A42B-449E7A2EA986"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:financial_transaction_manager:2.0.0.3:*:*:*:*:*:*:*","matchCriteriaId":"707B2AEE-74AD-48EE-8382-1193A4F858BE"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:financial_transaction_manager:2.1.0.0:*:*:*:*:*:*:*","matchCriteriaId":"2BA04226-260E-4048-BB02-19226DC2360B"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:financial_transaction_manager:2.1.0.1:*:*:*:*:*:*:*","matchCriteriaId":"240A1A0D-6967-4DE5-A92C-E9A6DC401E85"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:financial_transaction_manager:2.1.0.2:*:*:*:*:*:*:*","matchCriteriaId":"6516D058-8F4E-464C-A552-C04E0427AD8E"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.0:*:*:*:*:*:*:*","matchCriteriaId":"540CB2B6-7A52-46E0-BB86-CB696D2D5722"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.1:*:*:*:*:*:*:*","matchCriteriaId":"846CE234-EAB3-4D8A-894F-F97A1EDF4A8B"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.0:*:*:*:*:*:*:*","matchCriteriaId":"DD984921-7567-4A54-B23C-40D5250114DC"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:financial_transaction_manager_for_check_services:2.1.1.8:*:*:*:*:*:*:*","matchCriteriaId":"9FB0BED1-F7B6-4F97-9A93-BE81AA05C8C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:financial_transaction_manager_for_corporate_payment_services:2.1.1.0:*:*:*:*:*:*:*","matchCriteriaId":"C24501FA-B465-4209-B929-97BF90521B7A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"8917","Ordinal":"1","Title":"CVE-2014-8917","CVE":"CVE-2014-8917","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"8917","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3) dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in the IBM Dojo Toolkit, as used in IBM Social Media Analytics 1.3 before IF11 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.","Type":"Description","Title":"CVE-2014-8917"},{"CveYear":"2014","CveId":"8917","Ordinal":"2","NoteData":"2015-01-28","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"8917","Ordinal":"3","NoteData":"2017-09-07","Type":"Other","Title":"Modified"}]}}}