IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
| Software | From | Fixed in |
|---|---|---|
| ibm / hardware_management_console_r10.0_firmware | 10.0.245.0 | 10.0.245.0.x |
| ibm / hardware_management_console_r10.0_firmware | 10.1.3.0 | 10.1.3.0.x |
| ibm / hardware_management_console_r9.4_firmware | 89.40.83.0 | 89.40.83.0.x |
| ibm / hardware_management_console_r9.4_firmware | 89.41.25.0 | 89.41.25.0.x |
| ibm / hardware_management_console_r9.4_firmware | 89.42.18.0 | 89.42.18.0.x |
| ibm / hardware_management_console_r9.3_firmware | 89.33.45.0 | 89.33.45.0.x |
| ibm / hardware_management_console_r9.3_firmware | 89.33.52.0 | 89.33.52.0.x |