Cross-Site Scripting Vulnerability in IBM InfoSphere Master Data Management
CVE-2014-0968
Currently unrated
Key Information:
- Vendor
- IBM
- Status
- Vendor
- CVE Published:
- 19 July 2014
Summary
A Cross-Site Scripting (XSS) vulnerability exists in the GDS component of IBM InfoSphere Master Data Management, allowing remote authenticated users to inject malicious web scripts or HTML through specially crafted URLs for MHTML documents. This vulnerability affects versions 10.x and 11.x prior to 11.0 FP4, as well as versions 9.0 and 9.1 of the Product Information Management module, potentially compromising the security of affected systems.
References
Timeline
Vulnerability published
Vulnerability Reserved