4.3
CVSSv2

CVE-2014-6079

Published: 03/10/2014 Updated: 08/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Local Management Interface in IBM Security Access Manager for Web 7.x prior to 7.0.0-ISS-WGA-IF0009 and 8.x prior to 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x prior to 8.0.0-ISS-ISAM-FP0005, allows remote malicious users to inject arbitrary web script or HTML via a crafted URL.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.4

ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.3

ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.1

ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.0

ibm security_access_manager_for_mobile_appliance 8.0

ibm security_access_manager_for_web_7.0_firmware 7.0.0.1

ibm security_access_manager_for_web_7.0_firmware 7.0.0.2

ibm security_access_manager_for_web_7.0_firmware 7.0.0.3

ibm security_access_manager_for_web_7.0_firmware 7.0.0.4

ibm security_access_manager_for_web_7.0_firmware 7.0.0.5

ibm security_access_manager_for_web_7.0_firmware 7.0.0.6

ibm security_access_manager_for_web_7.0_firmware 7.0.0.0

ibm security_access_manager_for_web_7.0_firmware 7.0.0.7

ibm security_access_manager_for_web_7.0_firmware 7.0.0.8

ibm security_access_manager_for_web_appliance 7.0

ibm security_access_manager_for_web_8.0_firmware 8.0.0.2

ibm security_access_manager_for_web_8.0_firmware 8.0.0.3

ibm security_access_manager_for_web_8.0_firmware 8.0.0.4

ibm security_access_manager_for_web_appliance 8.0