Vulnerability Details CVE-2009-1288
Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to inject arbitrary web script or HTML via (1) the username in a login action or (2) the PATH parameter to private/file_management.ssi in the File manager.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.049
EPSS Ranking 89.0%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2009-1288
-
cpe:2.3:a:ibm:advanced_management_module:1.36h
-
cpe:2.3:h:ibm:bladecenter:e
-
cpe:2.3:h:ibm:bladecenter:h
-
cpe:2.3:h:ibm:bladecenter:hc10
-
cpe:2.3:h:ibm:bladecenter:hs12
-
cpe:2.3:h:ibm:bladecenter:hs20
-
cpe:2.3:h:ibm:bladecenter:hs21
-
cpe:2.3:h:ibm:bladecenter:hs21_xm
-
cpe:2.3:h:ibm:bladecenter:ht
-
cpe:2.3:h:ibm:bladecenter:js12
-
cpe:2.3:h:ibm:bladecenter:js21
-
cpe:2.3:h:ibm:bladecenter:js22
-
cpe:2.3:h:ibm:bladecenter:ls20
-
cpe:2.3:h:ibm:bladecenter:ls21
-
cpe:2.3:h:ibm:bladecenter:ls41
-
cpe:2.3:h:ibm:bladecenter:qs21
-
cpe:2.3:h:ibm:bladecenter:qs22
-
cpe:2.3:h:ibm:bladecenter:s
-
cpe:2.3:h:ibm:bladecenter:t