CVE-2010-4120

medium
Published 2010-10-28 · Modified 2026-04-29
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk
5.3

Description

Multiple cross-site scripting (XSS) vulnerabilities in the TAM console in IBM Tivoli Access Manager for e-business 6.1.0 before 6.1.0-TIV-TAM-FP0006 allow remote attackers to inject arbitrary web script or HTML via (1) the parm1 parameter to ivt/ivtserver, or the method parameter to (2) acl, (3) domain, (4) group, (5) gso, (6) gsogroup, (7) os, (8) pop, (9) rule, (10) user, or (11) webseal in ibm/wpm/.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.

✚ Propose a mitigation on Community → Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-34911 webapps multiple verified
IBM · 2010-10-22

IBM Tivoli Access Manager for E-Business - '/ibm/wpm/gso?method' Cross-Site Scripting

Source code queued for fetch — refresh in a moment.
EDB-34912 webapps multiple verified
IBM · 2010-10-22

IBM Tivoli Access Manager for E-Business - '/ibm/wpm/gsogroup?method' Cross-Site Scripting

Source code queued for fetch — refresh in a moment.
EDB-34913 webapps multiple verified
IBM · 2010-10-22

IBM Tivoli Access Manager for E-Business - '/ibm/wpm/os?method' Cross-Site Scripting

Source code queued for fetch — refresh in a moment.
EDB-34914 webapps multiple verified
IBM · 2010-10-22

IBM Tivoli Access Manager for E-Business - '/ibm/wpm/pop?method' Cross-Site Scripting

Source code queued for fetch — refresh in a moment.
EDB-34915 webapps multiple verified
IBM · 2010-10-22

IBM Tivoli Access Manager for E-Business - '/ibm/wpm/rule?method' Cross-Site Scripting

Source code queued for fetch — refresh in a moment.
EDB-34910 webapps multiple verified
IBM · 2010-10-22

IBM Tivoli Access Manager for E-Business - '/ibm/wpm/group?method' Cross-Site Scripting

Source code queued for fetch — refresh in a moment.
EDB-34908 webapps multiple verified
IBM · 2010-10-22

IBM Tivoli Access Manager for E-Business - '/ibm/wpm/acl?method' Cross-Site Scripting

Source code queued for fetch — refresh in a moment.
EDB-34909 webapps multiple verified
IBM · 2010-10-22

IBM Tivoli Access Manager for E-Business - '/ibm/wpm/domain?method' Cross-Site Scripting

Source code queued for fetch — refresh in a moment.
EDB-34916 webapps multiple verified
IBM · 2010-10-22

IBM Tivoli Access Manager for E-Business - '/ibm/wpm/user?method' Cross-Site Scripting

Source code queued for fetch — refresh in a moment.
EDB-34917 webapps multiple verified
IBM · 2010-10-22

IBM Tivoli Access Manager for E-Business - '/ibm/wpm/webseal?method' Cross-Site Scripting

Source code queued for fetch — refresh in a moment.
EDB-34907 webapps multiple verified
IBM · 2010-10-22

IBM Tivoli Access Manager for E-Business - '/ivt/ivtserver?parm1' Cross-Site Scripting

Source code queued for fetch — refresh in a moment.

Application impact

VendorProductVersionsFixed
ibm ibmtivoli_access_manager_for_e-business6.1.0
ibm ibmtivoli_access_manager_for_e-business6.1.1

References

CWEs

CWE-79

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.