CVE-2012-3328
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1, Maximo Asset Management Essentials 7.1, Tivoli Asset Management for IT 7.1 and 7.2, Tivoli Service Request Manager 7.1 and 7.2, and Change and Configuration Management Database (CCMDB) 7.1 and 7.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to a hidden frame footer.
Vulnerabilidad XSS en IBM Maximo Asset Management v7.1, Maximo Asset Management Essentials v7.1, Tivoli Asset Management para IT v7.1 y v7.2, Tivoli Service Request Manager v7.1 y v7.2, y Change y Configuration Management Database (CCMDB) v7.1 v 7.2, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de vectores que involucran a un marco (frame) oculto en el pie.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-06-07 CVE Reserved
- 2013-02-20 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/78040 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1IV20823 | 2017-08-29 | |
http://www-01.ibm.com/support/docview.wss?uid=swg21625624 | 2017-08-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Change And Configuration Management Database Search vendor "Ibm" for product "Change And Configuration Management Database" | 7.1. Search vendor "Ibm" for product "Change And Configuration Management Database" and version "7.1." | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Change And Configuration Management Database Search vendor "Ibm" for product "Change And Configuration Management Database" | 7.2.0 Search vendor "Ibm" for product "Change And Configuration Management Database" and version "7.2.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Maximo Asset Management Search vendor "Ibm" for product "Maximo Asset Management" | 7.1 Search vendor "Ibm" for product "Maximo Asset Management" and version "7.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Maximo Asset Management Essentials Search vendor "Ibm" for product "Maximo Asset Management Essentials" | 7.1 Search vendor "Ibm" for product "Maximo Asset Management Essentials" and version "7.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Asset Management For It Search vendor "Ibm" for product "Tivoli Asset Management For It" | 7.1 Search vendor "Ibm" for product "Tivoli Asset Management For It" and version "7.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Asset Management For It Search vendor "Ibm" for product "Tivoli Asset Management For It" | 7.2 Search vendor "Ibm" for product "Tivoli Asset Management For It" and version "7.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Service Request Manager Search vendor "Ibm" for product "Tivoli Service Request Manager" | 7.1.0 Search vendor "Ibm" for product "Tivoli Service Request Manager" and version "7.1.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Service Request Manager Search vendor "Ibm" for product "Tivoli Service Request Manager" | 7.1.0.0 Search vendor "Ibm" for product "Tivoli Service Request Manager" and version "7.1.0.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Service Request Manager Search vendor "Ibm" for product "Tivoli Service Request Manager" | 7.2.0.0 Search vendor "Ibm" for product "Tivoli Service Request Manager" and version "7.2.0.0" | - |
Affected
|