CVE-2012-3296 Information
Description
Cross-site scripting (XSS) vulnerability in the Help link in the login panel in IBM Power Hardware Management Console (HMC) 7R7.1.0 before SP4 7R7.2.0 before SP2 and 7R7.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Reference
http://secunia.com/advisories/50376 http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_the_help_link_on_the_power_hmc_login_panel_is_susceptible_to_reflected_cross_site_scripting_cve_2012_329617 http://www.ibm.com/support/docview.wss?uid=isg1MB03488 http://www.ibm.com/support/docview.wss?uid=isg1MB03489 http://www.ibm.com/support/docview.wss?uid=isg1MB03494 http://www.ibm.com/support/fixcentral/firmware/readme?fixid=MH01253 http://www.ibm.com/support/fixcentral/firmware/readme?fixid=MH01257 http://www.ibm.com/support/fixcentral/firmware/readme?fixid=MH01258 http://www.securitytracker.com/id?1027433 https://exchange.xforce.ibmcloud.com/vulnerabilities/77288
Share on: