Cross-Site Scripting Vulnerability in IBM InfoSphere Master Data Management
CVE-2014-0968

Currently unrated

Summary

A Cross-Site Scripting (XSS) vulnerability exists in the GDS component of IBM InfoSphere Master Data Management, allowing remote authenticated users to inject malicious web scripts or HTML through specially crafted URLs for MHTML documents. This vulnerability affects versions 10.x and 11.x prior to 11.0 FP4, as well as versions 9.0 and 9.1 of the Product Information Management module, potentially compromising the security of affected systems.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.