Multiple Cross-Site Scripting Vulnerabilities in IBM Tivoli Provisioning Manager Express
CVE-2007-6407

Currently unrated

Key Information:

Vendor

IBM

Vendor
CVE Published:
17 December 2007

What is CVE-2007-6407?

IBM Tivoli Provisioning Manager Express is susceptible to multiple cross-site scripting (XSS) vulnerabilities. These flaws enable remote attackers to inject arbitrary web scripts or HTML into the application. Specifically, attackers can exploit the 'assess modification' process, manipulate user-id fields, and use other unspecified inputs via the /tpmx URI, potentially compromising user data and application integrity.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.