Cross-site scripting (XSS) vulnerability in the Self Service UI (SSUI) in IBM Tivoli Identity Manager (ITIM) 5.0.0.5 allows remote authenticated users to inject arbitrary web script or HTML via the last name field in a profile.
References
Link | Resource |
---|---|
http://securitytracker.com/id?1022837 | |
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ54747 | Patch Vendor Advisory |
http://secunia.com/advisories/36511 | Vendor Advisory |
Configurations
Information
Published : 2009-09-18 14:30
Updated : 2009-09-20 21:00
NVD link : CVE-2009-3262
Mitre link : CVE-2009-3262
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
ibm
- tivoli_identity_manager