IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
References
Link | Resource |
---|---|
https://www.ibm.com/support/pages/node/7234276 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
History
09 Jun 2025, 18:51
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.ibm.com/support/pages/node/7234276 - Vendor Advisory | |
First Time |
Ibm hardware Management Console R10.0
Ibm hardware Management Console R10.0 Firmware Ibm hardware Management Console R9.3 Firmware Ibm hardware Management Console R9.4 Firmware Ibm hardware Management Console R9.4 Ibm hardware Management Console R9.3 Ibm |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
CPE | cpe:2.3:h:ibm:hardware_management_console_r10.0:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:hardware_management_console_r10.0_firmware:10.0.245.0:*:*:*:*:*:*:* cpe:2.3:o:ibm:hardware_management_console_r9.4_firmware:89.40.83.0:*:*:*:*:*:*:* cpe:2.3:o:ibm:hardware_management_console_r10.0_firmware:10.1.3.0:*:*:*:*:*:*:* cpe:2.3:o:ibm:hardware_management_console_r9.3_firmware:89.33.45.0:*:*:*:*:*:*:* cpe:2.3:o:ibm:hardware_management_console_r9.3_firmware:89.33.52.0:*:*:*:*:*:*:* cpe:2.3:o:ibm:hardware_management_console_r9.4_firmware:89.42.18.0:*:*:*:*:*:*:* cpe:2.3:h:ibm:hardware_management_console_r9.3:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:hardware_management_console_r9.4_firmware:89.41.25.0:*:*:*:*:*:*:* cpe:2.3:h:ibm:hardware_management_console_r9.4:-:*:*:*:*:*:*:* |
27 May 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-27 23:15
Updated : 2025-06-09 18:51
NVD link : CVE-2024-45094
Mitre link : CVE-2024-45094
JSON object : View
Products Affected
ibm
- hardware_management_console_r9.3_firmware
- hardware_management_console_r9.3
- hardware_management_console_r10.0_firmware
- hardware_management_console_r10.0
- hardware_management_console_r9.4_firmware
- hardware_management_console_r9.4
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')