Cross-Site Scripting Vulnerability in IBM Tivoli Storage Manager Operations Center
CVE-2016-6046

5.4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
1 February 2017

Summary

The Tivoli Storage Manager Operations Center by IBM is vulnerable to cross-site scripting (XSS) attacks, which could allow an attacker to inject malicious JavaScript into the web user interface. This vulnerability enables unauthorized users to manipulate the behavior of the application, potentially resulting in the disclosure of sensitive user credentials within a trusted browsing session. Maintaining robust web security measures is crucial to protect against such vulnerabilities.

Affected Version(s)

Tivoli Storage Manager Extended Edition 6.4

Tivoli Storage Manager Extended Edition 7.1

Tivoli Storage Manager Extended Edition 7.1.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.