Cross-Site Scripting Vulnerability in IBM Maximo Asset Management Products
CVE-2012-3328
Currently unrated
Key Information:
- Vendor
IBM
- Status
- Vendor
- CVE Published:
- 20 February 2013
What is CVE-2012-3328?
This vulnerability allows remote attackers to exploit web applications by injecting arbitrary web scripts or HTML into IBM Maximo Asset Management products. The risk arises from specific vectors associated with a hidden frame footer, potentially leading to unauthorized actions and data exposure. Attackers can leverage this vulnerability to execute malicious scripts in the context of the user’s session, compromising sensitive information and user integrity.