CVE-2018-11074
Summary
| CVE | CVE-2018-11074 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-28 18:29:00 UTC |
| Updated | 2020-03-27 14:07:00 UTC |
| Description | RSA Authentication Manager versions prior to 8.3 P3 are affected by a DOM-based cross-site scripting vulnerability which exists in its embedded MadCap Flare Help files. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to the browser DOM, which code is then executed by the web browser in the context of the vulnerable web application. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Emc | Rsa Authentication Manager | 8.3 | p1 | All | All |
| Application | Emc | Rsa Authentication Manager | 8.3 | p2 | All | All |
| Application | Emc | Rsa Authentication Manager | 8.3 | p1 | All | All |
| Application | Emc | Rsa Authentication Manager | 8.3 | p2 | All | All |
| Application | Rsa | Authentication Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: DSA-2018-152: RSA® Authentication Manager Multiple Vulnerabilities | FULLDISC | seclists.org | Mailing List, Third Party Advisory |
| RSA Authentication Manager Input Validation Flaws Let Remote Users Conduct Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| EMC RSA Authentication Manager Cross Site Scripting and HTML Injection Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: RSA would like to thank Mantas Juskauskas from SEC Consult Vulnerability for reporting CVE-2018-11074.
There are currently no legacy QID mappings associated with this CVE.