Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

IBM Tivoli Identity Manager Multiple Cross Site Scripting Vulnerabilities

Tivoli Identity Manager is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied data.

Attacker-supplied HTML or JavaScript code could run in an administrator's browser session in the context of the affected site. This could potentially allow the attacker to steal cookie-based authentication credentials; other attacks are also possible.

Tivoli Identity Manager 5.0 is vulnerable.







 

Privacy Statement
Copyright 2009, SecurityFocus