4.3

CVE-2009-1288

Exploit

Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to inject arbitrary web script or HTML via (1) the username in a login action or (2) the PATH parameter to private/file_management.ssi in the File manager.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmAdvanced Management Module Version1.36h
IbmBladecenter Versione Edition1881
IbmBladecenter Versione Edition7967
IbmBladecenter Versione Edition8677
IbmBladecenter Versionh Edition7989
IbmBladecenter Versionh Edition8852
IbmBladecenter Versionhc10 Edition7996
IbmBladecenter Versionhs12 Edition1916
IbmBladecenter Versionhs12 Edition8014
IbmBladecenter Versionhs12 Edition8028
IbmBladecenter Versionhs20 Edition1883
IbmBladecenter Versionhs21 Edition1885
IbmBladecenter Versionhs21 Edition8853
IbmBladecenter Versionhs21_xm Edition1915
IbmBladecenter Versionhs21_xm Edition7995
IbmBladecenter Versionht Edition8740
IbmBladecenter Versionht Edition8750
IbmBladecenter Versionjs12 Edition7998
IbmBladecenter Versionjs21 Edition7988
IbmBladecenter Versionjs21 Edition8844
IbmBladecenter Versionjs22 Edition7998
IbmBladecenter Versionls20 Edition8850
IbmBladecenter Versionls21 Edition7971
IbmBladecenter Versionls41 Edition7972
IbmBladecenter Versionqs21 Edition0792
IbmBladecenter Versionqs22 Edition0793
IbmBladecenter Versions Edition1948
IbmBladecenter Versions Edition8886
IbmBladecenter Versiont Edition8720
IbmBladecenter Versiont Edition8730
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.85% 0.885
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.