CVE-2018-1445

Severity
5.4MEDIUM
EPSS
0.3%
top 49.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 17
Latest updateMay 14

Description

IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139907.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

NVDibm/websphere_portal8.0.0.08.0.0.1+2
CVEListV5ibm/websphere_portal4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-qjwv-j352-5qp2: IBM WebSphere Portal 82022-05-14
CVEList
CVE-2018-1445: IBM WebSphere Portal 82018-04-17
CVE-2018-1445 (MEDIUM CVSS 5.4) | IBM WebSphere Portal 8.0.0 through | cvebase.io