CVE-2012-3327
Published Feb 20, 2013
Last updated 7 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to a login action.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F540E9A3-A1D7-4993-9149-295970944355" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:6.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA3625EE-DD32-43C1-8406-A23BD4DCD24E" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:6.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A6B68421-2A1E-4865-9F57-10C23F1D1ECD" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:6.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "97CC1505-74F4-4F2F-A44A-54D6B9836548" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:6.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FCB3D1DE-5702-4533-AFB6-FBCD2601681E" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:6.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "03E4240C-2BCD-4CDE-9134-E137759C22D3" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:6.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D7ED0B9-E115-42F3-A767-2DDE4D698723" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:6.2.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B6F450DA-21C6-4B8E-B3F6-38B9BB0571EA" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:6.2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7C76E3C7-EF50-419D-A79A-E68FBD44F3A4" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:6.2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D11C85F8-E4AA-4121-B8A6-5A2E56E5A05D" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:7.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F261A268-7CD0-4328-8FBB-6AC40927DDFC" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "537C2C01-302E-48A2-9D50-C98AB6DBC466" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "65C72B48-0C0F-4C90-A34B-528A5C67432C" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "59090B6A-09AE-4597-A60A-38C20AEA8F3E" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "74B7BC68-4BCB-4E02-9F6D-0F99DBE87FF0" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6FB99EBA-9725-4AB3-B816-5E00ADD7B7EC" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "19A4B2CD-94F5-4449-8D1F-E69C3BA9929C" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9F077F88-37D3-43FA-8EA6-A7FBD9869AA9" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "741A13F4-DED0-43A2-8761-AAEAA0557B96" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8945E452-7D50-4C59-B8CE-8F1C756DB01A" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4B590C42-21A1-4C62-8293-5A0D7AD628E4" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:maximo_asset_management_essentials:6.2.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2E041757-CFF1-4F3D-95FF-979BE37FCE0E" }, { "criteria": "cpe:2.3:a:ibm:maximo_asset_management_essentials:7.5.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FCA89D39-C008-49CD-9D1E-7109644970AB" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:tivoli_asset_management_for_it:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "62B69712-B405-43F4-B6E9-BC1C232A36E7" }, { "criteria": "cpe:2.3:a:ibm:tivoli_asset_management_for_it:6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "46711969-54C1-414A-B9F7-CCDCC4FFDA6A" }, { "criteria": "cpe:2.3:a:ibm:tivoli_asset_management_for_it:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E834D7A-9614-45BC-8361-27D80F14068D" }, { "criteria": "cpe:2.3:a:ibm:tivoli_asset_management_for_it:7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "013D299A-6A9C-44C7-B49C-A4115F4C13E3" }, { "criteria": "cpe:2.3:a:ibm:tivoli_asset_management_for_it:7.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3D5C1BCF-1DC0-45E7-B624-9221F8610346" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:tivoli_service_request_manager:7.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "54234F72-760A-4E80-8172-1AD93F0A372B" }, { "criteria": "cpe:2.3:a:ibm:tivoli_service_request_manager:7.1.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E1EE7E44-638B-4B42-88F3-F8E4019D8287" }, { "criteria": "cpe:2.3:a:ibm:tivoli_service_request_manager:7.2.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ED3A0A74-83FB-4061-8232-4BAA9D901B75" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:maximo_service_desk:6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B1D9DD16-F7C9-42E3-9E1D-36B4764C8503" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:change_and_configuration_management_database:7.1.:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13CD271A-72E0-4730-A936-87B5122D9E3D" }, { "criteria": "cpe:2.3:a:ibm:change_and_configuration_management_database:7.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2446CA6E-D316-4239-8FDC-436643EB35EA" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:smartcloud_control_desk:7.5.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83265FEF-C0CF-47B9-9A62-020897AABC5F" } ], "operator": "OR" } ] } ]