2014 m. rugsėjo 1 d., pirmadienis

IBM Maximo: Cross-site Scripting Vulnerability Addressed in Asset and Service Management (CVE-2014-0914 and -0915)

Two classes of persistent XSS issues we reported in IBM Maximo a month
or two back are now fixed:

http://www.pentestpartners.com/blog/further-ibm-maximo-asset-management-vulnerabilities-reported/

Individual bulletins linked from the above, but tl;dr is I would
suggest patching, as this could conceivably provide privilege
escalation routes for medium privilege users. Depends on what you're
doing and how much you trust your users.

cheers,
 Jamie

Komentarų nėra:

Rašyti komentarą