← Back

CVE-2018-1444

nvd nist
Published: Mar 14, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139906.

Affected (19)

1 product
Websphere Portal
Configuration A
19 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 8.5.0.0
Version 8.5.0.0 cf01
Version 8.5.0.0 cf02
Version 8.5.0.0 cf03
Version 8.5.0.0 cf04
Version 8.5.0.0 cf05
Version 8.5.0.0 cf06
Version 8.5.0.0 cf07
Version 8.5.0.0 cf08
Version 8.5.0.0 cf09
Version 8.5.0.0 cf10
Version 8.5.0.0 cf11
Version 8.5.0.0 cf12
Version 8.5.0.0 cf13
Version 8.5.0.0 cf14
Version 8.5.0.0 cf15
Version 9.0.0.0
Version 9.0.0.0 cf14
Version 9.0.0.0 cf15

References (6)

Source: psirt@us.ibm.com
Third Party AdvisoryVDB Entry
Source: psirt@us.ibm.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
VDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.