CVE-2024-45094: IBM DS8900F and DS8A00 Hardware Management Console (HMC) cross-site scripting
IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM System Storage DS8000 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45094?
CVE-2024-45094 is considered a high severity vulnerability due to its potential for stored cross-site scripting affecting privileged users.
How do I fix CVE-2024-45094?
To fix CVE-2024-45094, update your IBM DS8900F or DS8A00 Hardware Management Console to the latest patched version as recommended by IBM.
Who is affected by CVE-2024-45094?
The affected users include those utilizing IBM DS8900F, DS8A00, R10.0, R9.4, and R9.3 systems running specific versions listed in the vulnerability details.
What types of attacks can CVE-2024-45094 allow?
CVE-2024-45094 can allow an attacker to embed arbitrary JavaScript code in the Web UI, potentially leading to credential disclosure and unauthorized actions.
Is user interaction required for CVE-2024-45094?
Yes, user interaction is typically required to exploit CVE-2024-45094, as the vulnerability targets the Web UI accessed by privileged users.