Cross-Site Scripting Vulnerability in IBM InfoSphere Master Data Management
CVE-2014-0967

Currently unrated

Summary

A Cross-Site Scripting (XSS) vulnerability exists in IBM InfoSphere Master Data Management's GDS component, which can be exploited by remote authenticated users. By crafting a malicious URL, these users can inject arbitrary web script or HTML, potentially compromising user sessions or exposing sensitive data. This vulnerability affects versions of Collaborative Edition prior to 11.0 FP4 and both versions 9.0 and 9.1 of the Master Data Management Server for Product Information Management.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.