3.5
CVSSv2

CVE-2014-0824

Published: 26/05/2014 Updated: 29/08/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.x prior to 7.1.1.8 LAFIX.20140319-0839 and 7.1.1.12 before IFIX.20140321-1336 and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x prior to 7.1.1.8 LAFIX.20140319-0839 and 7.1.1.12 before IFIX.20140218-1510 allows remote authenticated users to inject arbitrary web script or HTML via an attachment URL.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm maximo service desk 7.1.1.7

ibm change and configuration management database 7.0

ibm change and configuration management database 7.1

ibm tivoli service request manager 7.1.1.8

ibm change and configuration management database 7.1.1.8

ibm tivoli service request manager 7.0

ibm tivoli service request manager 7.1.0

ibm maximo service desk 7.1.1.12

ibm tivoli it asset management for it 7.1.1.12

ibm maximo service desk 7.1.1.8

ibm change and configuration management database 7.1.1.7

ibm change and configuration management database 7.1.1.12

ibm tivoli it asset management for it 7.1.1.7

ibm tivoli service request manager 7.1.1

ibm tivoli service request manager 7.1.1.7

ibm tivoli service request manager 7.1.1.12

ibm tivoli it asset management for it 7.1.1.8

ibm maximo asset management 7.1.1.2

ibm maximo asset management 7.1.1.5

ibm maximo asset management 7.1.1.12

ibm maximo asset management 7.1

ibm maximo asset management 7.1.1.8

ibm maximo asset management 7.1.1.6

ibm maximo asset management 7.1.1.7

ibm maximo asset management 7.1.1

ibm maximo asset management 7.1.1.1