CVE-2012-0746

IBM Maximo Asset Mgmt 7.5 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Scores

EPSS 0.0018
EPSS Percentile 39.4%

Classification

CWE
CWE-79
Status published

Affected Products (12)

ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/maximo_asset_management
ibm/maximo_service_desk
ibm/smartcloud_control_desk
ibm/tivoli_asset_management_for_it
ibm/tivoli_asset_management_for_it
ibm/tivoli_asset_management_for_it
ibm/tivoli_asset_management_for_it
ibm/tivoli_asset_management_for_it
ibm/tivoli_service_request_manager
n/a/n/a

Timeline

Published Sep 10, 2012
Tracked Since Feb 18, 2026