IBM Rational Focal Point Unspecified Multiple HTML Injection Vulnerabilities
BID:65726
Info
IBM Rational Focal Point Unspecified Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 65726 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0853 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 20 2014 12:00AM |
| Updated: | Feb 25 2014 01:03AM |
| Credit: | Giuseppe Diego Gianni of NCIA/NCIRC |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IBM Rational Focal Point Unspecified Multiple HTML Injection Vulnerabilities
IBM Rational Focal Point is prone to unspecified multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
IBM Rational Focal Point 6.4, 6.4.1, 6.5, 6.5.1, 6.5.2, and 6.6 are vulnerable; other versions may also be affected.
IBM Rational Focal Point is prone to unspecified multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
IBM Rational Focal Point 6.4, 6.4.1, 6.5, 6.5.1, 6.5.2, and 6.6 are vulnerable; other versions may also be affected.
Exploit / POC
IBM Rational Focal Point Unspecified Multiple HTML Injection Vulnerabilities
An attacker can exploit these issues using a web browser.
An attacker can exploit these issues using a web browser.
Solution / Fix
IBM Rational Focal Point Unspecified Multiple HTML Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Rational Focal Point Unspecified Multiple HTML Injection Vulnerabilities
References:
References: