CVE-2018-8900
Summary
| CVE | CVE-2018-8900 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-02 21:29:00 UTC |
| Updated | 2018-06-14 01:29:00 UTC |
| Description | The License Manager service of HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE 7.80 allows remote attackers to inject malicious web script in the logs page of Admin Control Center (ACC) for cross-site scripting (XSS) vulnerability. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gemalto | Sentinel Ldk Rte | All | All | All | All |
| Application | Gemalto | Sentinel Ldk Rte | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cert-portal.siemens.com/productcert/pdf/ssa-566773.pdf | CONFIRM | cert-portal.siemens.com | |
| Sentinel LDK-SecurityBulletin-RTE7.8_v2_Final.pdf - Google Drive | MISC | drive.google.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.