IBM Tivoli Identity Manager Multiple Cross Site Scripting Vulnerabilities
BID:35566
Info
IBM Tivoli Identity Manager Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 35566 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-2316 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2009 12:00AM |
| Updated: | Apr 13 2015 09:09PM |
| Credit: | The vendor |
| Vulnerable: |
IBM Tivoli Identity Manager 4.6 IBM Tivoli Identity Manager 5.0 |
| Not Vulnerable: | |
Discussion
IBM Tivoli Identity Manager Multiple Cross Site Scripting Vulnerabilities
Tivoli Identity Manager is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in an administrator's browser session in the context of the affected site. This could potentially allow the attacker to steal cookie-based authentication credentials; other attacks are also possible.
Tivoli Identity Manager 5.0 is vulnerable.
Tivoli Identity Manager is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in an administrator's browser session in the context of the affected site. This could potentially allow the attacker to steal cookie-based authentication credentials; other attacks are also possible.
Tivoli Identity Manager 5.0 is vulnerable.
Exploit / POC
IBM Tivoli Identity Manager Multiple Cross Site Scripting Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
IBM Tivoli Identity Manager Multiple Cross Site Scripting Vulnerabilities
Solution:
Fixes are available; please see the references for details.
IBM Tivoli Identity Manager 4.6
Solution:
Fixes are available; please see the references for details.
IBM Tivoli Identity Manager 4.6
References
IBM Tivoli Identity Manager Multiple Cross Site Scripting Vulnerabilities
References:
References:
- swg24023640 IBM Tivoli Identity Manager, ver 5.0, Interim Fix 5.0.0.6-TIV-TIM-IF (IBM)
- Tivoli Identity Manager Homepage (IBM)
- IZ54310: 36107 - CORRECT XSS VULNERABILITES IN THE SELF-SERVICE UI INTERFACE (IBM)
- IZ54311: 36115 - CORRECT XSS VULNERABILITES IN THE ITIM CONSOLE INTERFACE (IBM)
- swg24023929 IBM Tivoli Identity Manager, ver 4.6.0, Interim Fix 4.6.0-TIV-TIM-IF (IBM)