CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
AI Score
Confidence
High
EPSS
Percentile
61.8%
Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to inject arbitrary web script or HTML via (1) the username in a login action or (2) the PATH parameter to private/file_management.ssi in the File manager.
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | advanced_management_module | 1.36h | cpe:2.3:a:ibm:advanced_management_module:1.36h:*:*:*:*:*:*:* |
ibm | bladecenter | e | cpe:2.3:h:ibm:bladecenter:e:*:1881:*:*:*:*:* |
ibm | bladecenter | e | cpe:2.3:h:ibm:bladecenter:e:*:7967:*:*:*:*:* |
ibm | bladecenter | e | cpe:2.3:h:ibm:bladecenter:e:*:8677:*:*:*:*:* |
ibm | bladecenter | h | cpe:2.3:h:ibm:bladecenter:h:*:7989:*:*:*:*:* |
ibm | bladecenter | h | cpe:2.3:h:ibm:bladecenter:h:*:8852:*:*:*:*:* |
ibm | bladecenter | hc10 | cpe:2.3:h:ibm:bladecenter:hc10:*:7996:*:*:*:*:* |
ibm | bladecenter | hs12 | cpe:2.3:h:ibm:bladecenter:hs12:*:1916:*:*:*:*:* |
ibm | bladecenter | hs12 | cpe:2.3:h:ibm:bladecenter:hs12:*:8014:*:*:*:*:* |
ibm | bladecenter | hs12 | cpe:2.3:h:ibm:bladecenter:hs12:*:8028:*:*:*:*:* |