Информационная безопасность
[RU] switch to English


Дополнительная информация

  Межсайтовый скриптинг в IBM Maximo

From:Jamie Riden <jamie.riden_(at)_gmail.com>
Date:26 августа 2014 г.
Subject:IBM Maximo: Cross-site Scripting Vulnerability Addressed in Asset and Service Management (CVE-2014-0914 and -0915)



Two classes of persistent XSS issues we reported in IBM Maximo a month
or two back are now fixed:

http://www.pentestpartners.com/blog/further-ibm-maximo-asset-management-vulnerabi
lities-reported/


Individual bulletins linked from the above, but tl;dr is I would
suggest patching, as this could conceivably provide privilege
escalation routes for medium privilege users. Depends on what you're
doing and how much you trust your users.

cheers,
Jamie
-- Jamie Riden / [email protected] / [email protected] http://uk.linkedin.com/in/jamieriden

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород