← Back

CVE-2018-10934

nvd nist
Published: Mar 27, 2019Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.

Affected (3)

2 products
Single Sign On
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 7.0
Running on/withPlatform Versions
Redhat
Enterprise Linux Server
Version 6.0
Redhat
Enterprise Linux Server
Version 7.0
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.1.0
Version 7.2

References (12)

Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.