Multiple IBM Products CVE-2015-0108 Unspecified Cross Site Scripting Vulnerability
BID:72704
Info
Multiple IBM Products CVE-2015-0108 Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 72704 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-0108 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 28 2015 12:00AM |
| Updated: | Jan 28 2015 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM Tivoli Service Request Manager 7.2 IBM Tivoli Service Request Manager 7.1 IBM Tivoli Asset Management for IT 7.2 IBM Tivoli Asset Management for IT 7.1 IBM Maximo for Utilities 7.1 IBM Maximo for Transportation 7.1 IBM Maximo for Oil and Gas 7.1 IBM Maximo for Nuclear Power 7.1 IBM Maximo for Life Sciences 7.1 IBM Maximo for Government 7.1 IBM Maximo Asset Management Essentials 7.1 IBM Maximo Asset Management 7.1 IBM Change and Configuration Management Database 7.2 IBM Change and Configuration Management Database 7.1 |
| Not Vulnerable: | |
Discussion
Multiple IBM Products CVE-2015-0108 Unspecified Cross Site Scripting Vulnerability
Multiple IBM products are prone to an unspecified cross-site scripting vulnerability because it fails to sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Multiple IBM products are prone to an unspecified cross-site scripting vulnerability because it fails to sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.