CVE-2018-10934
published 2019-03-27CVE-2018-10934: A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create…
PriorityP423medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.95%
57.2th percentile
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | wildfly-core | — | — |
| red_hat | wildfly-core | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fw7x-p3x6-x9p7: A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7
ghsa_unreviewed·2022-05-14
CVE-2018-10934 [MEDIUM] CWE-79 GHSA-fw7x-p3x6-x9p7: A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.
Red Hat
wildfly-core: Cross-site scripting (XSS) in JBoss Management Console
vendor_redhat·2018-08-14·CVSS 5.4
CVE-2018-10934 [MEDIUM] CWE-79 wildfly-core: Cross-site scripting (XSS) in JBoss Management Console
wildfly-core: Cross-site scripting (XSS) in JBoss Management Console
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.
Package: wildfly-core (Red Hat BPM Suite 6) - Out of support scope
Package: wildfly-core (Red Hat Decision Manager 7) - Not affected
Package: wildfly-core (Red Hat JBoss BRMS 6) - Out of support scope
Package: wildfly-core (Red Hat JBoss Data Grid 7) - Not affected
Package: wildfly-core (Red Hat JBoss Data Virtualization 6) - Out of support scope
Package: wildfly (Red Hat JBoss Enterprise Application Platform 7) - Affected
Package: wildfly-core (Red Hat JBoss Fuse 6) - Out of support s
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2019:1159https://access.redhat.com/errata/RHSA-2019:1160https://access.redhat.com/errata/RHSA-2019:1161https://access.redhat.com/errata/RHSA-2019:1162https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10934https://security.netapp.com/advisory/ntap-20190611-0002/https://access.redhat.com/errata/RHSA-2019:1159https://access.redhat.com/errata/RHSA-2019:1160https://access.redhat.com/errata/RHSA-2019:1161https://access.redhat.com/errata/RHSA-2019:1162https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10934https://security.netapp.com/advisory/ntap-20190611-0002/
2019-03-27
Published