cbcvebase.
CVE-2015-7451
published 2016-01-02

CVE-2015-7451: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.9 IF2 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5…

medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.9 IF2 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 IF2, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

Affected

12 ranges
VendorProductVersion rangeFixed in
ibmmaximo_asset_management
ibmmaximo_asset_management
ibmmaximo_asset_management_essentials
ibmmaximo_for_government
ibmmaximo_for_life_sciences
ibmmaximo_for_life_sciences
ibmmaximo_for_nuclear_power
ibmmaximo_for_oil_and_gas
ibmmaximo_for_transportation
ibmmaximo_for_utilities
ibmsmartcloud_control_desk
ibmsmartcloud_control_desk