PT-2013-2421 · Ibm · Ibm Tivoli Monitoring+1
Ewerson Guimarães
·
Published
2013-06-21
·
Updated
2017-08-29
·
CVE-2013-0548
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Monitoring (ITM) versions 6.2.0 through 6.2.3 before FP3
IBM Application Manager for Smart Business version 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004
Description
The issue allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, which can lead to cross-site scripting (XSS) attacks. This can potentially affect a large number of devices worldwide, although the exact number is not specified.
Recommendations
For IBM Tivoli Monitoring (ITM) versions 6.2.0 through 6.2.3 before FP3, update to a version that includes FP3 or later to resolve the issue.
For IBM Application Manager for Smart Business version 1.2.1, update to version 1.2.1.0-TIV-IAMSB-FP0004 or later to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Application Manager For Smart Business
Ibm Tivoli Monitoring