IBM Rational Focal Point CVE-2014-0843 Unspecified HTML Injection Vulnerability
BID:65730
Info
IBM Rational Focal Point CVE-2014-0843 Unspecified HTML Injection Vulnerability
| Bugtraq ID: | 65730 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0843 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2014 12:00AM |
| Updated: | Feb 21 2014 12:00AM |
| Credit: | Giuseppe Diego Gianni, NCIA/NCIRC |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IBM Rational Focal Point CVE-2014-0843 Unspecified HTML Injection Vulnerability
IBM Rational Focal Point is prone to an unspecified HTML-injection vulnerability.
Successful exploits will result in the execution of arbitrary attacker-supplied HTML and script code in the context of the affected application, potentially allowing the attacker to steal cookie-based authentication credentials or control how the page is rendered to the user. Other attacks are also possible.
IBM Rational Focal Point 6.4.0, 6.4.1, 6.5, 6.5.1, 6.5.2 and 6.6 are vulnerable.
IBM Rational Focal Point is prone to an unspecified HTML-injection vulnerability.
Successful exploits will result in the execution of arbitrary attacker-supplied HTML and script code in the context of the affected application, potentially allowing the attacker to steal cookie-based authentication credentials or control how the page is rendered to the user. Other attacks are also possible.
IBM Rational Focal Point 6.4.0, 6.4.1, 6.5, 6.5.1, 6.5.2 and 6.6 are vulnerable.
Exploit / POC
IBM Rational Focal Point CVE-2014-0843 Unspecified HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
IBM Rational Focal Point CVE-2014-0843 Unspecified HTML Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Rational Focal Point CVE-2014-0843 Unspecified HTML Injection Vulnerability
References:
References: