Cross-Site Scripting Vulnerability in IBM Maximo Asset Management Products
CVE-2014-0825
Currently unrated
Key Information:
- Vendor
IBM
- Status
- Vendor
- CVE Published:
- 26 May 2014
What is CVE-2014-0825?
A cross-site scripting vulnerability exists in the IBM Maximo Asset Management product suite, allowing remote authenticated users to craft a malicious report parameter that injects arbitrary web scripts or HTML. This affects various versions of IBM Maximo, SmartCloud Control Desk, and Tivoli IT Asset Management, potentially compromising the integrity of the application and the security of user data.