CVE-2014-0915

IBM Maximo Asset Management < 7.5.0.6 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.2, and 7.2 for Tivoli Asset Management for IT and certain other products allow remote authenticated users to inject arbitrary web script or HTML via (1) the KPI display name field or (2) a portlet field.

Scores

EPSS 0.0030
EPSS Percentile 53.2%

Details

CWE
CWE-79
Status published
Products (50)
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management
... and 40 more
Published Jul 30, 2014
Tracked Since Feb 18, 2026