[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Cross-site scripting (XSS) vulnerability in Web Reports in IBM Tivoli Endpoint Manager

ID: oval:org.secpod.oval:def:10552Date: (C)2013-03-28   (M)2021-06-02
Class: VULNERABILITYFamily: windows




The host is installed with IBM Tivoli Endpoint Manager (TEM) 8.0 before 8.2.1372 and is prone to cross-site scripting (XSS) vulnerability. A flaw is present in the application, which fails to properly sanitize user-supplied input. Successful exploitation allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

Platform:
Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows 8
Microsoft Windows Server 2012
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product:
IBM Tivoli Endpoint Manager
Reference:
CVE-2013-0453
CVE    1
CVE-2013-0453
CPE    4
cpe:/a:ibm:tivoli_endpoint_manager
cpe:/a:ibm:tivoli_endpoint_manager:8.2
cpe:/a:ibm:tivoli_endpoint_manager:8.1
cpe:/a:ibm:tivoli_endpoint_manager:8.0
...

© SecPod Technologies