CVE-2009-1288

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
13/04/2009
Last modified:
09/04/2025

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to inject arbitrary web script or HTML via (1) the username in a login action or (2) the PATH parameter to private/file_management.ssi in the File manager.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:advanced_management_module:1.36h:*:*:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:e:*:1881:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:e:*:7967:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:e:*:8677:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:h:*:7989:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:h:*:8852:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hc10:*:7996:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs12:*:1916:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs12:*:8014:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs12:*:8028:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs20:*:1883:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs21:*:1885:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs21:*:8853:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs21_xm:*:1915:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs21_xm:*:7995:*:*:*:*:*