4.3
CVE-2011-1395
- EPSS 1.15%
- Veröffentlicht 13.03.2012 03:12:25
- Zuletzt bearbeitet 16.06.2026 23:29:15
- Erkennungen
Cross-site scripting (XSS) vulnerability in imicon.jsp in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote attackers to inject arbitrary web script or HTML via the controlid parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Maximo Asset Management Version 6.2
Ibm ≫ Maximo Asset Management Version 7.1
Ibm ≫ Maximo Asset Management Version 7.5
Ibm ≫ Maximo Asset Management Essentials Version 6.2
Ibm ≫ Maximo Asset Management Essentials Version 7.1
Ibm ≫ Maximo Asset Management Essentials Version 7.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.15% | 0.632 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
http://secunia.com/advisories/48299
http://www.ibm.com/support/docview.wss?uid=swg21584666
http://www.securityfocus.com/bid/52333
http://www-01.ibm.com/support/docview.wss?uid=swg1IV09189
https://exchange.xforce.ibmcloud.com/vulnerabilities/71996