IBM WebSphere Application Server/Virtual Enterprise CVE-2018-1926 Cross Site Scripting Vulnerability
BID:106204
CVE-2018-1926 |Info
IBM WebSphere Application Server/Virtual Enterprise CVE-2018-1926 Cross Site Scripting Vulnerability
| Bugtraq ID: | 106204 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-1926 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2018 12:00AM |
| Updated: | Dec 10 2018 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM WebSphere Virtual Enterprise 8.0 IBM WebSphere Virtual Enterprise 7 IBM Websphere Application Server 9.0.0.9 IBM Websphere Application Server 9.0.0.8 IBM Websphere Application Server 9.0.0.7 IBM Websphere Application Server 9.0.0.6 IBM Websphere Application Server 9.0.0.5 IBM Websphere Application Server 9.0.0.4 IBM Websphere Application Server 9.0.0.3 IBM Websphere Application Server 9.0.0.2 IBM Websphere Application Server 9.0.0.1 IBM Websphere Application Server 9.0.0.0 IBM Websphere Application Server 9.0 IBM Websphere Application Server 8.5.5.9 IBM Websphere Application Server 8.5.5.8 IBM Websphere Application Server 8.5.5.7 IBM Websphere Application Server 8.5.5.6 IBM Websphere Application Server 8.5.5.5 IBM Websphere Application Server 8.5.5.4 IBM Websphere Application Server 8.5.5.3 IBM Websphere Application Server 8.5.5.2 IBM Websphere Application Server 8.5.5.14 IBM Websphere Application Server 8.5.5.13 IBM Websphere Application Server 8.5.5.12 IBM Websphere Application Server 8.5.5.11 IBM Websphere Application Server 8.5.5.1 IBM Websphere Application Server 8.5.5.0 IBM Websphere Application Server 8.5.0.2 IBM Websphere Application Server 8.5.0.1 IBM Websphere Application Server 8.5 |
| Not Vulnerable: |
IBM Websphere Application Server 9.0.0.10 IBM Websphere Application Server 8.5.5.15 |
Exploit / POC
IBM WebSphere Application Server/Virtual Enterprise CVE-2018-1926 Cross Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
IBM WebSphere Application Server/Virtual Enterprise CVE-2018-1926 Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.