3.5
CVSSv2

CVE-2014-0825

Published: 26/05/2014 Updated: 29/08/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in openreport.jsp in IBM Maximo Asset Management 7.x prior to 7.1.1.12 IFIX.20140321-1336 and 7.5.x prior to 7.5.0.5 IFIX006; SmartCloud Control Desk 7.x prior to 7.5.0.3 and 7.5.1.x prior to 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x prior to 7.1.1.12 IFIX.20140218-1510 allows remote authenticated users to inject arbitrary web script or HTML via a crafted report parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm change and configuration management database 7.0

ibm tivoli service request manager 7.0

ibm tivoli service request manager 7.1.0

ibm tivoli it asset management for it 7.1.1.11

ibm tivoli it asset management for it 7.1.1.12

ibm change and configuration management database 7.1.1.12

ibm change and configuration management database 7.1.1.7

ibm maximo service desk 7.1.1.11

ibm tivoli service request manager 7.1.1.11

ibm tivoli service request manager 7.1.1.12

ibm change and configuration management database 7.1

ibm change and configuration management database 7.1.1.11

ibm tivoli service request manager 7.1.0.0

ibm tivoli service request manager 7.1.1

ibm maximo service desk 7.1.1.12

ibm maximo service desk 7.1.1.7

ibm tivoli service request manager 7.1.1.7

ibm tivoli it asset management for it 7.1.1.7

ibm smartcloud control desk 7.5.0.1

ibm smartcloud control desk 7.5.0.2

ibm smartcloud control desk 7.5.1.1

ibm smartcloud control desk 7.0

ibm smartcloud control desk 7.5.1.0

ibm smartcloud control desk 7.5

ibm smartcloud control desk 7.5.0.0

ibm maximo asset management 7.1

ibm maximo asset management 7.1.1

ibm maximo asset management 7.1.1.6

ibm maximo asset management 7.1.1.7

ibm maximo asset management 7.5.0.2

ibm maximo asset management 7.5.0.3

ibm maximo asset management 7.1.1.11

ibm maximo asset management 7.1.1.12

ibm maximo asset management 7.5.0.0

ibm maximo asset management 7.5.0.1

ibm maximo asset management 7.1.1.1

ibm maximo asset management 7.1.1.10

ibm maximo asset management 7.1.1.8

ibm maximo asset management 7.1.1.9

ibm maximo asset management 7.5.0.4

ibm maximo asset management 7.5.0.5

ibm maximo asset management 7.1.1.2

ibm maximo asset management 7.1.1.5