CVE-2012-2172

IBM DS Storage Manager Host Software < 10.83 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote attackers to inject arbitrary web script or HTML via the updateRegn parameter.

Exploits (1)

exploitdb WRITEUP
by LiquidWorm · textwebappswindows
https://www.exploit-db.com/exploits/19321

Scores

EPSS 0.0631
EPSS Percentile 90.8%

Classification

CWE
CWE-79
Status published

Affected Products (22)

ibm/ds_storage_manager_host_software < 10.83
ibm/ds_storage_manager_host_software
ibm/ds_storage_manager_host_software
ibm/ds4100
ibm/ds4100
ibm/ds4200
ibm/ds4300
ibm/ds4400
ibm/ds4500
ibm/ds4700
ibm/ds4800
ibm/system_storage_dcs3700_storage_subsystem
ibm/system_storage_ds3200
ibm/system_storage_ds3300
ibm/system_storage_ds3400
... and 7 more

Timeline

Published Jun 22, 2012
Tracked Since Feb 18, 2026