CVE-2014-0914
IBM Maximo Asset Management < 7.5.0.6 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 6.x and 7.x through 7.5.0.6, Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 6.2 through 6.2.8 for Tivoli IT Asset Management for IT and Maximo Service Desk allows remote authenticated users to inject arbitrary web script or HTML via the Query Description Field.
References (7)
Scores
EPSS
0.0030
EPSS Percentile
53.2%
Details
CWE
CWE-79
Status
published
Products (50)
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management
... and 40 more
Published
Jul 30, 2014
Tracked Since
Feb 18, 2026