CVE-2015-4944
06.10.2015, 01:59
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX003, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX003 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Vendor | Product | Version |
---|---|---|
ibm | change_and_configuration_management_database | 7.1 |
ibm | change_and_configuration_management_database | 7.2 |
ibm | maximo_asset_management | 7.1 |
ibm | maximo_asset_management | 7.1.1 |
ibm | maximo_asset_management | 7.1.1.1 |
ibm | maximo_asset_management | 7.1.1.2 |
ibm | maximo_asset_management | 7.1.1.5 |
ibm | maximo_asset_management | 7.1.1.6 |
ibm | maximo_asset_management | 7.1.1.7 |
ibm | maximo_asset_management | 7.1.1.8 |
ibm | maximo_asset_management | 7.1.1.9 |
ibm | maximo_asset_management | 7.1.1.10 |
ibm | maximo_asset_management | 7.1.1.11 |
ibm | maximo_asset_management | 7.1.1.12 |
ibm | maximo_asset_management | 7.1.1.13 |
ibm | maximo_asset_management | 7.5.0.0 |
ibm | maximo_asset_management | 7.5.0.1 |
ibm | maximo_asset_management | 7.5.0.2 |
ibm | maximo_asset_management | 7.5.0.3 |
ibm | maximo_asset_management | 7.5.0.4 |
ibm | maximo_asset_management | 7.5.0.5 |
ibm | maximo_asset_management | 7.5.0.6 |
ibm | maximo_asset_management | 7.5.0.7 |
ibm | maximo_asset_management | 7.5.0.8 |
ibm | maximo_asset_management | 7.6.0.0 |
ibm | maximo_asset_management_essentials | 7.1 |
ibm | maximo_asset_management_essentials | 7.5 |
ibm | maximo_for_energy_optimization | 7.1 |
ibm | maximo_for_government | 7.1 |
ibm | maximo_for_government | 7.5.0.0 |
ibm | maximo_for_government | 7.5.0.1 |
ibm | maximo_for_government | 7.5.0.2 |
ibm | maximo_for_government | 7.5.0.3 |
ibm | maximo_for_government | 7.5.0.4 |
ibm | maximo_for_government | 7.5.0.5 |
ibm | maximo_for_government | 7.5.0.6 |
ibm | maximo_for_life_sciences | 7.1 |
ibm | maximo_for_life_sciences | 7.5.0.0 |
ibm | maximo_for_life_sciences | 7.5.0.1 |
ibm | maximo_for_life_sciences | 7.5.0.2 |
ibm | maximo_for_life_sciences | 7.5.0.3 |
ibm | maximo_for_life_sciences | 7.5.0.4 |
ibm | maximo_for_life_sciences | 7.5.0.5 |
ibm | maximo_for_life_sciences | 7.5.0.6 |
ibm | maximo_for_nuclear_power | 7.1 |
ibm | maximo_for_nuclear_power | 7.5.0.0 |
ibm | maximo_for_nuclear_power | 7.5.0.1 |
ibm | maximo_for_nuclear_power | 7.5.0.2 |
ibm | maximo_for_nuclear_power | 7.5.0.3 |
ibm | maximo_for_nuclear_power | 7.5.0.4 |
ibm | maximo_for_nuclear_power | 7.5.0.5 |
ibm | maximo_for_nuclear_power | 7.5.0.6 |
ibm | maximo_for_oil_and_gas | 7.1 |
ibm | maximo_for_oil_and_gas | 7.5.0.0 |
ibm | maximo_for_oil_and_gas | 7.5.0.1 |
ibm | maximo_for_oil_and_gas | 7.5.0.2 |
ibm | maximo_for_oil_and_gas | 7.5.0.3 |
ibm | maximo_for_oil_and_gas | 7.5.0.4 |
ibm | maximo_for_oil_and_gas | 7.5.0.5 |
ibm | maximo_for_oil_and_gas | 7.5.0.6 |
ibm | maximo_for_transportation | 7.1 |
ibm | maximo_for_transportation | 7.5.0.0 |
ibm | maximo_for_transportation | 7.5.0.1 |
ibm | maximo_for_transportation | 7.5.0.2 |
ibm | maximo_for_transportation | 7.5.0.3 |
ibm | maximo_for_transportation | 7.5.0.4 |
ibm | maximo_for_transportation | 7.5.0.5 |
ibm | maximo_for_transportation | 7.5.0.6 |
ibm | maximo_for_utilities | 7.1 |
ibm | maximo_for_utilities | 7.5.0.0 |
ibm | maximo_for_utilities | 7.5.0.1 |
ibm | maximo_for_utilities | 7.5.0.2 |
ibm | maximo_for_utilities | 7.5.0.3 |
ibm | maximo_for_utilities | 7.5.0.4 |
ibm | maximo_for_utilities | 7.5.0.5 |
ibm | maximo_for_utilities | 7.5.0.6 |
ibm | smartcloud_control_desk | 7.5 |
ibm | tivoli_asset_management_for_it | 7.1 |
ibm | tivoli_asset_management_for_it | 7.2 |
ibm | tivoli_service_request_manager | 7.1.0 |
ibm | tivoli_service_request_manager | 7.2.0.0 |
𝑥
= Vulnerable software versions