CVE-2014-0915
30.07.2014, 11:15
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.2, and 7.2 for Tivoli Asset Management for IT and certain other products allow remote authenticated users to inject arbitrary web script or HTML via (1) the KPI display name field or (2) a portlet field.
Vendor | Product | Version |
---|---|---|
ibm | maximo_asset_management | 6.2 |
ibm | maximo_asset_management | 6.2.1 |
ibm | maximo_asset_management | 6.2.2 |
ibm | maximo_asset_management | 6.2.3 |
ibm | maximo_asset_management | 6.2.4 |
ibm | maximo_asset_management | 6.2.5 |
ibm | maximo_asset_management | 6.2.6 |
ibm | maximo_asset_management | 6.2.6.1 |
ibm | maximo_asset_management | 6.2.7 |
ibm | maximo_asset_management | 6.2.8 |
ibm | maximo_asset_management | 7.1 |
ibm | maximo_asset_management | 7.1.1 |
ibm | maximo_asset_management | 7.1.1.1 |
ibm | maximo_asset_management | 7.1.1.2 |
ibm | maximo_asset_management | 7.1.1.5 |
ibm | maximo_asset_management | 7.1.1.6 |
ibm | maximo_asset_management | 7.1.1.7 |
ibm | maximo_asset_management | 7.1.1.8 |
ibm | maximo_asset_management | 7.1.1.9 |
ibm | maximo_asset_management | 7.1.1.10 |
ibm | maximo_asset_management | 7.1.1.11 |
ibm | maximo_asset_management | 7.1.1.12 |
ibm | maximo_asset_management | 7.1.2 |
ibm | maximo_asset_management | 7.5.0.0 |
ibm | maximo_asset_management | 7.5.0.1 |
ibm | maximo_asset_management | 7.5.0.2 |
ibm | maximo_asset_management | 7.5.0.3 |
ibm | maximo_asset_management | 7.5.0.4 |
ibm | maximo_asset_management | 7.5.0.5 |
ibm | maximo_asset_management | 7.5.0.6 |
ibm | maximo_asset_management | 7.5.0.10 |
ibm | maximo_asset_management_essentials | 𝑥 ≤ 7.5.0.6 |
ibm | maximo_asset_management_essentials | 6.2.0.0 |
ibm | maximo_asset_management_essentials | 7.1 |
ibm | maximo_asset_management_essentials | 7.5.0.0 |
ibm | maximo_asset_management_essentials | 7.5.0.1 |
ibm | maximo_asset_management_essentials | 7.5.0.2 |
ibm | maximo_asset_management_essentials | 7.5.0.3 |
ibm | maximo_asset_management_essentials | 7.5.0.4 |
ibm | maximo_asset_management_essentials | 7.5.0.5 |
ibm | maximo_for_government | 𝑥 ≤ 7.5.0.6 |
ibm | maximo_for_government | 7.1 |
ibm | maximo_for_government | 7.5.0.0 |
ibm | maximo_for_government | 7.5.0.1 |
ibm | maximo_for_government | 7.5.0.2 |
ibm | maximo_for_government | 7.5.0.3 |
ibm | maximo_for_government | 7.5.0.4 |
ibm | maximo_for_government | 7.5.0.5 |
ibm | maximo_for_life_sciences | 𝑥 ≤ 7.5.0.6 |
ibm | maximo_for_life_sciences | 7.1 |
ibm | maximo_for_life_sciences | 7.5.0.0 |
ibm | maximo_for_life_sciences | 7.5.0.1 |
ibm | maximo_for_life_sciences | 7.5.0.2 |
ibm | maximo_for_life_sciences | 7.5.0.3 |
ibm | maximo_for_life_sciences | 7.5.0.4 |
ibm | maximo_for_life_sciences | 7.5.0.5 |
ibm | maximo_for_nuclear_power | 𝑥 ≤ 7.5.0.6 |
ibm | maximo_for_nuclear_power | 7.1 |
ibm | maximo_for_nuclear_power | 7.5.0.0 |
ibm | maximo_for_nuclear_power | 7.5.0.1 |
ibm | maximo_for_nuclear_power | 7.5.0.2 |
ibm | maximo_for_nuclear_power | 7.5.0.3 |
ibm | maximo_for_nuclear_power | 7.5.0.4 |
ibm | maximo_for_nuclear_power | 7.5.0.5 |
ibm | maximo_for_oil_and_gas | 𝑥 ≤ 7.5.0.6 |
ibm | maximo_for_oil_and_gas | 7.1 |
ibm | maximo_for_oil_and_gas | 7.5.0.0 |
ibm | maximo_for_oil_and_gas | 7.5.0.1 |
ibm | maximo_for_oil_and_gas | 7.5.0.2 |
ibm | maximo_for_oil_and_gas | 7.5.0.3 |
ibm | maximo_for_oil_and_gas | 7.5.0.4 |
ibm | maximo_for_oil_and_gas | 7.5.0.5 |
ibm | maximo_for_transportation | 𝑥 ≤ 7.5.0.6 |
ibm | maximo_for_transportation | 7.1 |
ibm | maximo_for_transportation | 7.5.0.0 |
ibm | maximo_for_transportation | 7.5.0.1 |
ibm | maximo_for_transportation | 7.5.0.2 |
ibm | maximo_for_transportation | 7.5.0.3 |
ibm | maximo_for_transportation | 7.5.0.4 |
ibm | maximo_for_transportation | 7.5.0.5 |
ibm | maximo_for_utilities | 𝑥 ≤ 7.5.0.6 |
ibm | maximo_for_utilities | 7.1 |
ibm | maximo_for_utilities | 7.5.0.0 |
ibm | maximo_for_utilities | 7.5.0.1 |
ibm | maximo_for_utilities | 7.5.0.2 |
ibm | maximo_for_utilities | 7.5.0.3 |
ibm | maximo_for_utilities | 7.5.0.4 |
ibm | maximo_for_utilities | 7.5.0.5 |
ibm | maximo_service_desk | 𝑥 ≤ 6.2.8 |
ibm | smartcloud_control_desk | 𝑥 ≤ 7.5.0.6 |
ibm | smartcloud_control_desk | 7.5 |
ibm | smartcloud_control_desk | 7.5.0.0 |
ibm | smartcloud_control_desk | 7.5.0.1 |
ibm | smartcloud_control_desk | 7.5.0.2 |
ibm | smartcloud_control_desk | 7.5.0.3 |
ibm | smartcloud_control_desk | 7.5.1.0 |
ibm | smartcloud_control_desk | 7.5.1.1 |
ibm | smartcloud_control_desk | 7.5.1.2 |
ibm | tivoli_it_asset_management_for_it | 𝑥 ≤ 6.2.8 |
𝑥
= Vulnerable software versions
References