CVE-2018-10934
Summary
| CVE | CVE-2018-10934 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-27 13:29:00 UTC |
| Updated | 2019-06-11 23:29:00 UTC |
| Description | A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Linux Server | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 7.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 7.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 7.1.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 7.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 7.1.0 | All | All | All |
| Application | Redhat | Single Sign-on | 7.2 | All | All | All |
| Application | Redhat | Single Sign-on | 7.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| CVE-2018-10934 JBoss Enterprise Application Platform Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| 1615673 – (CVE-2018-10934) CVE-2018-10934 wildfly-core: Cross-site scripting (XSS) in JBoss Management Console | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.