CVE-2018-1253
Summary
| CVE | CVE-2018-1253 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-21 15:29:00 UTC |
| Updated | 2020-03-27 14:07:00 UTC |
| Description | RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulnerability. A malicious Operations Console administrator could potentially exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console administrators open the affected page, the injected scripts could potentially be executed in their browser. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Emc | Rsa Authentication Manager | 7.1 | - | All | All |
| Application | Emc | Rsa Authentication Manager | 7.1 | sp2 | All | All |
| Application | Emc | Rsa Authentication Manager | 7.1 | sp3 | All | All |
| Application | Emc | Rsa Authentication Manager | 7.1 | sp4 | All | All |
| Application | Emc | Rsa Authentication Manager | 8.0 | - | All | All |
| Application | Emc | Rsa Authentication Manager | 8.0 | p1 | All | All |
| Application | Emc | Rsa Authentication Manager | 8.1 | - | All | All |
| Application | Emc | Rsa Authentication Manager | 8.1 | sp1 | All | All |
| Application | Emc | Rsa Authentication Manager | 8.2 | - | All | All |
| Application | Emc | Rsa Authentication Manager | 8.2 | sp1 | All | All |
| Application | Emc | Rsa Authentication Manager | 8.3 | - | All | All |
| Application | Emc | Rsa Authentication Manager | 8.3 | p1 | All | All |
| Application | Emc | Rsa Authentication Manager | 7.1 | - | All | All |
| Application | Emc | Rsa Authentication Manager | 7.1 | sp2 | All | All |
| Application | Emc | Rsa Authentication Manager | 7.1 | sp3 | All | All |
| Application | Emc | Rsa Authentication Manager | 7.1 | sp4 | All | All |
| Application | Emc | Rsa Authentication Manager | 8.0 | - | All | All |
| Application | Emc | Rsa Authentication Manager | 8.0 | p1 | All | All |
| Application | Emc | Rsa Authentication Manager | 8.1 | - | All | All |
| Application | Emc | Rsa Authentication Manager | 8.1 | sp1 | All | All |
| Application | Emc | Rsa Authentication Manager | 8.2 | - | All | All |
| Application | Emc | Rsa Authentication Manager | 8.2 | sp1 | All | All |
| Application | Emc | Rsa Authentication Manager | 8.3 | - | All | All |
| Application | Emc | Rsa Authentication Manager | 8.3 | p1 | All | All |
| Application | Emc | Rsa Authentication Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: DSA-2018-107: RSA Authentication Manager Cross-site scripting Vulnerabilities | FULLDISC | seclists.org | Mailing List, Third Party Advisory |
| RSA Authentication Manager Input Validation Flaws Let Remote Users Conduct Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| EMC RSA Authentication Manager Cross Site Scripting and HTML Injection Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.