CVE-2011-4819 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management and Asset Management Essentials 6.2 7.1 and 7.5 allow remote attackers to inject arbitrary web script or HTML via the uisesionid parameter to (1) maximo.jsp or (2) the default URI under ui/.

Reference

http://secunia.com/advisories/48299 http://www.ibm.com/support/docview.wss?uid=swg21584666 http://www.securityfocus.com/bid/52333 http://www-01.ibm.com/support/docview.wss?uid=swg1IV09202 https://exchange.xforce.ibmcloud.com/vulnerabilities/72008

Share on: