CVE-2024-45094

IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
References
Link Resource
https://www.ibm.com/support/pages/node/7234276 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:ibm:hardware_management_console_r10.0_firmware:10.0.245.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:hardware_management_console_r10.0_firmware:10.1.3.0:*:*:*:*:*:*:*
cpe:2.3:h:ibm:hardware_management_console_r10.0:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:ibm:hardware_management_console_r9.4_firmware:89.40.83.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:hardware_management_console_r9.4_firmware:89.41.25.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:hardware_management_console_r9.4_firmware:89.42.18.0:*:*:*:*:*:*:*
cpe:2.3:h:ibm:hardware_management_console_r9.4:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:ibm:hardware_management_console_r9.3_firmware:89.33.45.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:hardware_management_console_r9.3_firmware:89.33.52.0:*:*:*:*:*:*:*
cpe:2.3:h:ibm:hardware_management_console_r9.3:-:*:*:*:*:*:*:*

History

09 Jun 2025, 18:51

Type Values Removed Values Added
First Time Ibm
Ibm hardware Management Console R9.3 Firmware
Ibm hardware Management Console R9.4 Firmware
Ibm hardware Management Console R9.4
Ibm hardware Management Console R10.0 Firmware
Ibm hardware Management Console R10.0
Ibm hardware Management Console R9.3
References () https://www.ibm.com/support/pages/node/7234276 - () https://www.ibm.com/support/pages/node/7234276 - Vendor Advisory
CPE cpe:2.3:o:ibm:hardware_management_console_r10.0_firmware:10.0.245.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:hardware_management_console_r9.4_firmware:89.42.18.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:hardware_management_console_r10.0_firmware:10.1.3.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:hardware_management_console_r9.4_firmware:89.41.25.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:hardware_management_console_r9.3_firmware:89.33.45.0:*:*:*:*:*:*:*
cpe:2.3:h:ibm:hardware_management_console_r10.0:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:hardware_management_console_r9.3_firmware:89.33.52.0:*:*:*:*:*:*:*
cpe:2.3:h:ibm:hardware_management_console_r9.3:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:hardware_management_console_r9.4:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:hardware_management_console_r9.4_firmware:89.40.83.0:*:*:*:*:*:*:*

28 May 2025, 15:01

Type Values Removed Values Added
Summary
  • (es) IBM DS8900F y DS8A00 Hardware Management Console (HMC) es vulnerable a Cross-Site Scripting almacenado. Esta vulnerabilidad permite a un usuario con privilegios incrustar código JavaScript arbitrario en la interfaz web, alterando así la funcionalidad prevista y pudiendo provocar la divulgación de credenciales en una sesión de confianza.

27 May 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-27 23:15

Updated : 2025-06-09 18:51


NVD link : CVE-2024-45094

Mitre link : CVE-2024-45094

CVE.ORG link : CVE-2024-45094


JSON object : View

Products Affected

ibm

  • hardware_management_console_r10.0_firmware
  • hardware_management_console_r9.4
  • hardware_management_console_r10.0
  • hardware_management_console_r9.4_firmware
  • hardware_management_console_r9.3
  • hardware_management_console_r9.3_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')