IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
References
Link | Resource |
---|---|
https://www.ibm.com/support/pages/node/7234276 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
History
09 Jun 2025, 18:51
Type | Values Removed | Values Added |
---|---|---|
First Time |
Ibm
Ibm hardware Management Console R9.3 Firmware Ibm hardware Management Console R9.4 Firmware Ibm hardware Management Console R9.4 Ibm hardware Management Console R10.0 Firmware Ibm hardware Management Console R10.0 Ibm hardware Management Console R9.3 |
|
References | () https://www.ibm.com/support/pages/node/7234276 - Vendor Advisory | |
CPE | cpe:2.3:o:ibm:hardware_management_console_r10.0_firmware:10.0.245.0:*:*:*:*:*:*:* cpe:2.3:o:ibm:hardware_management_console_r9.4_firmware:89.42.18.0:*:*:*:*:*:*:* cpe:2.3:o:ibm:hardware_management_console_r10.0_firmware:10.1.3.0:*:*:*:*:*:*:* cpe:2.3:o:ibm:hardware_management_console_r9.4_firmware:89.41.25.0:*:*:*:*:*:*:* cpe:2.3:o:ibm:hardware_management_console_r9.3_firmware:89.33.45.0:*:*:*:*:*:*:* cpe:2.3:h:ibm:hardware_management_console_r10.0:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:hardware_management_console_r9.3_firmware:89.33.52.0:*:*:*:*:*:*:* cpe:2.3:h:ibm:hardware_management_console_r9.3:-:*:*:*:*:*:*:* cpe:2.3:h:ibm:hardware_management_console_r9.4:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:hardware_management_console_r9.4_firmware:89.40.83.0:*:*:*:*:*:*:* |
28 May 2025, 15:01
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
27 May 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-27 23:15
Updated : 2025-06-09 18:51
NVD link : CVE-2024-45094
Mitre link : CVE-2024-45094
CVE.ORG link : CVE-2024-45094
JSON object : View
Products Affected
ibm
- hardware_management_console_r10.0_firmware
- hardware_management_console_r9.4
- hardware_management_console_r10.0
- hardware_management_console_r9.4_firmware
- hardware_management_console_r9.3
- hardware_management_console_r9.3_firmware
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')