Description
IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected products
- IBM Corporation / Tivoli Storage Manager Extended Edition6.4 – 6.4
- IBM Corporation / Tivoli Storage Manager Extended Edition7.1 – 7.1
- IBM Corporation / Tivoli Storage Manager Extended Edition7.1.1 – 7.1.1
- IBM Corporation / Tivoli Storage Manager Extended Edition6.1 – 6.1
- IBM Corporation / Tivoli Storage Manager Extended Edition6.2 – 6.2
- IBM Corporation / Tivoli Storage Manager Extended Edition6.3 – 6.3