Unrated severityNVD Advisory· Published Jul 5, 2009· Updated Apr 23, 2026
CVE-2009-2316
CVE-2009-2316
Description
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote attackers to inject arbitrary web script or HTML by entering an unspecified URL in (1) the self-service UI interface or (2) the console interface. NOTE: it was later reported that 4.6.0 is also affected by the first vector.
Affected products
2cpe:2.3:a:ibm:tivoli_identity_manager:5.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:tivoli_identity_manager:5.0:*:*:*:*:*:*:*
- (no CPE)range: 5.0, 4.6.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- www-01.ibm.com/support/docview.wssnvdPatchVendor Advisory
- secunia.com/advisories/35696nvdVendor Advisory
- www-01.ibm.com/support/docview.wssnvdVendor Advisory
- osvdb.org/55550nvd
- osvdb.org/55551nvd
- secunia.com/advisories/36119nvd
- www-01.ibm.com/support/docview.wssnvd
- www-01.ibm.com/support/docview.wssnvd
- www-01.ibm.com/support/docview.wssnvd
- www.securityfocus.com/bid/35566nvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2009/1774nvd
- www.vupen.com/english/advisories/2009/2106nvd
News mentions
0No linked articles in our index yet.