CVE-2014-0870
IBM Algo Credit Limits - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to inject arbitrary web script or HTML via (1) the Message parameter to rcore6/main/showerror.jsp, (2) the ButtonsetClass parameter to rcore6/main/buttonset.jsp, (3) the MBName parameter to rcore6/frameset.jsp, (4) the Init parameter to algopds/rcore6/main/browse.jsp, or the (5) Name, (6) StoreName, or (7) STYLESHEET parameter to algopds/rcore6/main/ibrowseheader.jsp.
Exploits (1)
References (7)
Scores
EPSS
0.0940
EPSS Percentile
92.7%
Details
CWE
CWE-79
Status
published
Products (4)
ibm/algo_credit_limits
ibm/algo_credit_limits
ibm/algorithmics
n/a/n/a
Published
Jul 07, 2014
Tracked Since
Feb 18, 2026