Cross-Site Scripting Vulnerabilities in IBM Maximo Asset Management
CVE-2014-3025

Currently unrated

Key Information:

Summary

IBM Maximo Asset Management contains multiple XSS vulnerabilities that allow remote authenticated users to inject arbitrary web scripts or HTML code. These vulnerabilities can be triggered through unspecified input to a .jsp file within the webclient/utility/ directory, impacting versions 6.2 through 6.2.8, 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6. Malicious users could exploit these weaknesses to conduct unauthorized actions in the affected web applications, potentially compromising sensitive data or user sessions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.