CVE-2017-1218
published 2017-07-19CVE-2017-1218: IBM Tivoli Endpoint Manager is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted…
PriorityP337high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
0.90%
55.5th percentile
IBM Tivoli Endpoint Manager is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123858.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | bigfix_family | — | — |
| ibm | bigfix_family | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
| ibm | bigfix_platform | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7463 business-central: Reflected XSS in artifact upload error message
bugzilla·2017-04-06·CVSS 6.1
CVE-2017-7463 [MEDIUM] CVE-2017-7463 business-central: Reflected XSS in artifact upload error message
CVE-2017-7463 business-central: Reflected XSS in artifact upload error message
It was found that file upload functionality in business central allows javascript code to be included in the file that is executed via error message as it's being showed in HTML mode.
Upstream bug:
https://issues.jboss.org/browse/RHBPMS-4627
Discussion:
Acknowledgments:
Name: Chris Hebert, Vikas Pandey, Harold Schliesske, Ryan Stanley (Noblis)
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.4.3
Via RHSA-2017:1218 https://access.redhat.com/errata/RHSA-2017:1218
---
This issue has been addressed in the following products:
Red Hat JBoss BRMS 6.4.3
Via RHSA-2017:1217 https://access.redhat.com/errata/RHSA-2017:1217
Bugzilla
CVE-2017-2674 business-central: Multiple stored XSS in task and process filters
bugzilla·2017-04-06·CVSS 6.1
CVE-2017-2674 [MEDIUM] CVE-2017-2674 business-central: Multiple stored XSS in task and process filters
CVE-2017-2674 business-central: Multiple stored XSS in task and process filters
It was found that Task Filter List in business central accepts HTML tags in the Name field. When creating a new task filtered list with crafted Name field and deleting it, HTML code is rendered.
Upstream bug:
https://issues.jboss.org/browse/RHBPMS-4625
Discussion:
Acknowledgments:
Name: Chris Hebert, Vikas Pandey, Harold Schliesske, Ryan Stanley (Noblis)
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.4.3
Via RHSA-2017:1218 https://access.redhat.com/errata/RHSA-2017:1218
---
This issue has been addressed in the following products:
Red Hat JBoss BRMS 6.4.3
Via RHSA-2017:1217 https://access.redhat.com/errata/RHSA-2017:1217
http://www.ibm.com/support/docview.wss?uid=swg22005246http://www.securityfocus.com/bid/101571http://www.securityfocus.com/bid/99916https://exchange.xforce.ibmcloud.com/vulnerabilities/123858http://www.ibm.com/support/docview.wss?uid=swg22005246http://www.securityfocus.com/bid/101571http://www.securityfocus.com/bid/99916https://exchange.xforce.ibmcloud.com/vulnerabilities/123858
2017-07-19
Published