IBM Tivoli Netcool/OMNIbus Multiple Security Vulnerabilities
BID:66219
Info
IBM Tivoli Netcool/OMNIbus Multiple Security Vulnerabilities
| Bugtraq ID: | 66219 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0942 CVE-2014-0941 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2014 12:00AM |
| Updated: | May 14 2014 01:12AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IBM Tivoli Netcool/OMNIbus Multiple Security Vulnerabilities
IBM Tivoli Netcool/OMNIbus is prone to the following security vulnerabilities:
1. Multiple cross-site scripting vulnerabilities
2. An unspecified security vulnerability
An attacker can exploit these issues to execute attacker-supplied HTML or JavaScript code in the context of the affected site, to steal cookie-based authentication credentials.
IBM Tivoli Netcool/OMNIbus prior to 7.4.0 Fix Pack 2 are vulnerable.
IBM Tivoli Netcool/OMNIbus is prone to the following security vulnerabilities:
1. Multiple cross-site scripting vulnerabilities
2. An unspecified security vulnerability
An attacker can exploit these issues to execute attacker-supplied HTML or JavaScript code in the context of the affected site, to steal cookie-based authentication credentials.
IBM Tivoli Netcool/OMNIbus prior to 7.4.0 Fix Pack 2 are vulnerable.
Exploit / POC
IBM Tivoli Netcool/OMNIbus Multiple Security Vulnerabilities
Attackers can exploit this issue using a browser or readily available tools.
Attackers can exploit this issue using a browser or readily available tools.
Solution / Fix
IBM Tivoli Netcool/OMNIbus Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Tivoli Netcool/OMNIbus Multiple Security Vulnerabilities
References:
References:
- IBM Homepage (IBM)
- Tivoli Netcool/OMNIbus Homepage (IBM)