CVE-2014-6137

IBM Tivoli Endpoint Manager < 9.1.1117 - Cross-Site Scripting in Relay Diagnostic Page

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-6137. PoCs published by RedTeam Pentesting.

AI-analyzed exploit summary The advisory describes a persistent XSS vulnerability in IBM Endpoint Manager Relay Diagnostics page, where the 'url' parameter in a specific CGI script is susceptible to JavaScript injection. The injected code is stored and executed when the diagnostics page is accessed.

Description

Cross-site scripting (XSS) vulnerability in the Relay Diagnostic page in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Exploits (1)

exploitdb WRITEUP
by RedTeam Pentesting · textwebappscgi
https://www.exploit-db.com/exploits/36057

The advisory describes a persistent XSS vulnerability in IBM Endpoint Manager Relay Diagnostics page, where the 'url' parameter in a specific CGI script is susceptible to JavaScript injection. The injected code is stored and executed when the diagnostics page is accessed.

Classification
Writeup 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: IBM Endpoint Manager versions earlier than 9.1.1229 and 9.2.1.48
No auth needed
Prerequisites: Access to the IBM Endpoint Manager Relay Diagnostics page
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/96817
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21692516
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72559

Scores

EPSS 0.0225
EPSS Percentile 80.6%

Details

CWE
CWE-79
Status published
Products (1)
ibm/tivoli_endpoint_manager < 9.1.1117
Published Feb 16, 2015
Tracked Since Feb 18, 2026