Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10934

Опубликовано: 14 авг. 2018
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6wildfly-coreOut of support scope
Red Hat Decision Manager 7wildfly-coreNot affected
Red Hat JBoss BRMS 6wildfly-coreOut of support scope
Red Hat JBoss Data Grid 7wildfly-coreNot affected
Red Hat JBoss Data Virtualization 6wildfly-coreOut of support scope
Red Hat JBoss Enterprise Application Platform 7wildflyAffected
Red Hat JBoss Fuse 6wildfly-coreOut of support scope
Red Hat JBoss Operations Network 3wildfly-coreOut of support scope
Red Hat Process Automation 7wildfly-coreNot affected
Red Hat Single Sign-On 7wildfly-coreNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1615673wildfly-core: Cross-site scripting (XSS) in JBoss Management Console

EPSS

Процентиль: 62%
0.00431
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
почти 7 лет назад

A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.

CVSS3: 5.4
debian
почти 7 лет назад

A cross-site scripting (XSS) vulnerability was found in the JBoss Mana ...

CVSS3: 5.4
github
больше 3 лет назад

A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.

EPSS

Процентиль: 62%
0.00431
Низкий

5.4 Medium

CVSS3

Уязвимость CVE-2018-10934