CVE-2014-6175

IBM Marketing Operations 7.x-9.1.1.x - Authenticated Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before 9.0.0.4.1, 9.1.0.x before 9.1.0.5, and 9.1.1.x before 9.1.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

References (4)

Core 4
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21902933
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PO04455
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PO02715
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PO03923

Scores

EPSS 0.0097
EPSS Percentile 58.0%

Details

CWE
CWE-79
Status published
Products (50)
ibm/marketing_operations 7.2.0.0
ibm/marketing_operations 7.2.0.4
ibm/marketing_operations 7.2.1.0
ibm/marketing_operations 7.2.1.12
ibm/marketing_operations 7.3.2.0
ibm/marketing_operations 7.3.2.1
ibm/marketing_operations 7.3.2.8
ibm/marketing_operations 7.4.0.0
ibm/marketing_operations 7.4.0.2
ibm/marketing_operations 7.4.1.0
... and 40 more
Published Jun 07, 2015
Tracked Since Feb 18, 2026