5.4

CVE-2018-6495

MFSBGN03808 rev.1 - Micro Focus UCMDB, Cross-Site Scripting

Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microfocus ≫ Universal Cmdb Version 0.20
Microfocus ≫ Universal Cmdb Version 10.21
Microfocus ≫ Universal Cmdb Version 10.22
Microfocus ≫ Universal Cmdb Version 10.30
Microfocus ≫ Universal Cmdb Version 10.31
Microfocus ≫ Universal Cmdb Version 10.32
Microfocus ≫ Universal Cmdb Version 10.33
Microfocus ≫ Universal Cmdb Version 11.0
Microfocus ≫ Universal Cmdb Browser Version 4.15.1
Microfocus ≫ Cms Server Version 4.10
Microfocus ≫ Cms Server Version 4.11
Microfocus ≫ Cms Server Version 4.12
Microfocus ≫ Cms Server Version 4.13
Microfocus ≫ Cms Server Version 4.14
Microfocus ≫ Cms Server Version 4.15.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.65% 0.464
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
NIST 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
OpenText 6.3 2.1 4.2
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://www.securitytracker.com/id/1040970
https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03164778