← Back

CVE-2013-5402

nvd nist
Published: Dec 18, 2013Modified: Apr 29, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management, Maximo Asset Management Essentials, Maximo for Government, Maximo for Nuclear Power, Maximo for Transportation, Maximo for Life Sciences, Maximo for Oil and Gas, and Maximo for Utilities 7.1.x through 7.1.1.12, 7.1.2, 7.5 before 7.5.0.3 IFIX014, and 7.5.0.5 before IFIX003; SmartCloud Control Desk (SCCD) 7.5 before 7.5.0.3 IFIX014 and 7.5.0.5 before IFIX003; and Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.1.x through 7.1.1.12, 7.1.2, and 7.2.x through 7.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Affected (85)

12 products
Maximo Asset Management
Maximo For Government
Maximo For Life Sciences
Maximo For Nuclear Power
Maximo For Oil And Gas
Maximo For Transportation
Maximo For Utilities
Smartcloud Control Desk
Tivoli Asset Management For It
Tivoli Service Request Manager
Configuration A
67 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 7.1.1.10
Version 7.1.1.11
Version 7.1.1.12
Version 7.1.1.1
Version 7.1.1.2
Version 7.1.1.5
Version 7.1.1.6
Version 7.1.1.7
Version 7.1.1.8
Version 7.1.1.9
Version 7.1.1
Version 7.1.2
Version 7.1
Version 7.5.0.0
Version 7.5.0.1
Version 7.5.0.2
Version 7.5.0.3
Version 7.5.0.5
Ibm
Version 7.1
Version 7.5.0.0
Version 7.5.0.1
Version 7.5.0.2
Version 7.5.0.3
Version 7.5.0.4
Version 7.5.0.5
Ibm
Version 7.1
Version 7.5.0.0
Version 7.5.0.1
Version 7.5.0.2
Version 7.5.0.3
Version 7.5.0.4
Version 7.5.0.5
Ibm
Version 7.1
Version 7.5.0.0
Version 7.5.0.1
Version 7.5.0.2
Version 7.5.0.3
Version 7.5.0.4
Version 7.5.0.5
Ibm
Version 7.1
Version 7.5.0.0
Version 7.5.0.1
Version 7.5.0.2
Version 7.5.0.3
Version 7.5.0.4
Version 7.5.0.5
Ibm
Version 7.1
Version 7.5.0.0
Version 7.5.0.1
Version 7.5.0.2
Version 7.5.0.3
Version 7.5.0.4
Version 7.5.0.5
Ibm
Version 7.1
Version 7.5.0.0
Version 7.5.0.1
Version 7.5.0.2
Version 7.5.0.3
Version 7.5.0.4
Version 7.5.0.5
Ibm
Version 7.1
Version 7.5.0.0
Version 7.5.0.1
Version 7.5.0.2
Version 7.5.0.3
Version 7.5.0.4
Version 7.5.0.5
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 7.5.0.0
Version 7.5.0.1
Version 7.5.0.2
Version 7.5.0.3
Version 7.5.0.5
Configuration C
13 vulnerable

References (8)

Source: psirt@us.ibm.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.