Cross-Site Scripting Vulnerabilities in IBM Algorithmics RICOS
CVE-2014-0870

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
7 July 2014

Summary

Multiple cross-site scripting vulnerabilities exist in IBM Algorithmics RICOS, impacting versions 4.5.0 through 4.7.0 before 4.7.0.03 FP5. Attackers can exploit these vulnerabilities by injecting arbitrary web scripts via several parameters, including Message, ButtonsetClass, MBName, Init, Name, StoreName, and STYLESHEET in different JSP files. This can lead to unauthorized actions and access to sensitive information within affected applications.

References

EPSS Score

10% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.