Release date:
Updated on:
Affected Systems:
IBM Hardware Management Console
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2012-3296
The IBM Hardware Management Console (HMC) is a system management device used to control systems and communicate with controlled systems.
Some inputs passed to the logon Panel through "Help link" on the IBM Hardware Management Console (HMC) R7.1.0, R7.2.0, and R7.3.0 are returned to the user if they are not properly filtered, attackers can execute arbitrary HTML and script code in the user's browser.
<* Source: CitiGroup, Inc.
Link: http://secunia.com/advisories/50376/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ers.ibm.com/