CVE-2014-6100 - CVE House
Back to Database
Status published Low CVE-2014-6100

Cross-site scripting (XSS) vulnerability in the Admin UI in IBM...

Vulnerability Description

Cross-site scripting (XSS) vulnerability in the Admin UI in IBM Tivoli Directory Server 6.1 before 6.1.0.64-ISS-ITDS-IF0064, 6.2 before 6.2.0.39-ISS-ITDS-FP0039, and 6.3 before 6.3.0.33-ISS-ITDS-IF0033, and IBM Security Directory Server 6.3.1 before 6.3.1.7-ISS-ISDS-IF0007, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-6100

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

security directory server, tivoli directory server
Vulnerable Versions:
6.3.1, 6.3.1.1, 6.3.1.2, 6.3.1.3, 6.3.1.4, 6.3.1.5, 6.3.1.6, 6.1.0, 6.1.0.0, 6.1.0.1, 6.1.0.2, 6.1.0.3, 6.1.0.4, 6.1.0.5, 6.1.0.6, 6.1.0.7, 6.1.0.8, 6.1.0.9, 6.1.0.10, 6.1.0.11, 6.1.0.12, 6.1.0.13, 6.1.0.14, 6.1.0.15, 6.1.0.17, 6.1.0.18, 6.1.0.19, 6.1.0.20, 6.1.0.21, 6.1.0.22, 6.1.0.23, 6.1.0.24, 6.1.0.25, 6.1.0.26, 6.1.0.27, 6.1.0.28, 6.1.0.29, 6.1.0.30, 6.1.0.31, 6.1.0.32, 6.1.0.33, 6.1.0.34, 6.1.0.35, 6.1.0.36, 6.1.0.37, 6.1.0.38, 6.1.0.39, 6.1.0.45, 6.1.0.46, 6.1.0.47, 6.1.0.48, 6.1.0.63, 6.2, 6.2.0, 6.2.0.0, 6.2.0.1, 6.2.0.2, 6.2.0.3, 6.2.0.4, 6.2.0.5, 6.2.0.6, 6.2.0.7, 6.2.0.8, 6.2.0.10, 6.2.0.11, 6.2.0.12, 6.2.0.13, 6.2.0.14, 6.2.0.15, 6.2.0.19, 6.2.0.20, 6.2.0.21, 6.2.0.22, 6.2.0.38, 6.3.0, 6.3.0.0, 6.3.0.1, 6.3.0.2, 6.3.0.8, 6.3.0.9, 6.3.0.10, 6.3.0.32

Timeline

Official Publish: October 19th, 2014
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.