IBM Global Console Manager switches Multiple XSS Vulnerabilities

Summary
This host is installed with IBM Global Console Manager switches and is prone to multiple xss vulnerabilities.
Impact
Successful exploitation will allow attacker to execute arbitrary HTML and script code in a user's browser session in the context of an affected site. Impact Level: Application
Solution
Update to firmware version 1.20.20.23447 or newer, For updates refer http://www.ibm.com
Insight
Flaw is due to improper sanitization of user-supplied input passed via 'query' parameter to kvm.cgi and 'key' parameter to avctalert.php script.
Affected
IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447
Detection
Send a crafted request via HTTP GET and check whether it is able to read cookie or not.
References