PT-2014-3892 · Ibm · Ibm Infosphere Master Data Management Reference Data Management (Rdm) Hub
Publicado
2014-03-16
·
Atualizado
2017-08-29
·
CVE-2014-0850
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM InfoSphere Master Data Management Reference Data Management (RDM) Hub versions 10.1 through 11.0 before 11.0.0.0-MDM-IF008
Description
The issue allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, which is a result of a cross-site scripting (XSS) vulnerability. Cross-site scripting (XSS) is a type of security vulnerability that occurs when an attacker is able to inject malicious scripts into a website, allowing them to steal user data or take control of the user's session.
Recommendations
For IBM InfoSphere Master Data Management Reference Data Management (RDM) Hub version 10.1, update to a version after 11.0.0.0-MDM-IF008.
For IBM InfoSphere Master Data Management Reference Data Management (RDM) Hub version 11.0 before 11.0.0.0-MDM-IF008, update to version 11.0.0.0-MDM-IF008 or later.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Infosphere Master Data Management Reference Data Management (Rdm) Hub