CVE-2018-1916
published 2019-03-14CVE-2018-1916: IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to…
PriorityP424medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.97%
57.7th percentile
IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152740.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | 5.0 – 6.0.6 | — |
| ibm | rational_doors_next_generation | 5.0 – 6.0.6 | — |
| ibm | rational_engineering_lifecycle_manager | 5.0 – 6.0.6 | — |
| ibm | rational_quality_manager | 5.0 – 6.0.6 | — |
| ibm | rational_rhapsody_design_manager | 5.0 – 6.0.6 | — |
| ibm | rational_software_architect_design_manager | 5.0 – 6.0.1 | — |
| ibm | rational_team_concert | 5.0 – 6.0.6 | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10931 cobbler: CobblerXMLRPCInterface exports all its methods over XMLRPC
bugzilla·2018-08-08·CVSS 9.8
CVE-2018-10931 [CRITICAL] CVE-2018-10931 cobbler: CobblerXMLRPCInterface exports all its methods over XMLRPC
CVE-2018-10931 cobbler: CobblerXMLRPCInterface exports all its methods over XMLRPC
Cobbler CobblerXMLRPCInterface object exposes all its functions over XMLRPC. This allows an attacker to use internal the internal functions of the class, such as creating a token, or upload files.
Upstream issue:
https://github.com/cobbler/cobbler/issues/1916
Upstream patch:
https://github.com/cobbler/cobbler/pull/1921
References:
https://movermeyer.com/2018-08-02-privilege-escalation-exploits-in-cobblers-api/
Discussion:
Acknowledgments:
Name: Cedric Buissart (Red Hat)
---
Created attachment 1474535
fix
---
Created cobbler tracking bugs for this issue:
Affects: epel-all [bug 1614431]
Affects: fedora-all [bug 1614433]
---
This issue has been addressed in the following products:
Red Hat Sate
Bugzilla
CVE-2018-1000226 cobbler: XMLRPC API endpoints are not correctly validating security tokens
bugzilla·2018-08-03·CVSS 9.8
CVE-2018-1000226 [CRITICAL] CVE-2018-1000226 cobbler: XMLRPC API endpoints are not correctly validating security tokens
CVE-2018-1000226 cobbler: XMLRPC API endpoints are not correctly validating security tokens
It was found that in cobbler's XMLRPC API there are many places where the user supplied security token is not being correctly validated, effectively resulting in authentication being bypassed.
Upstream issue:
https://github.com/cobbler/cobbler/issues/1916
References:
https://movermeyer.com/2018-08-02-privilege-escalation-exploits-in-cobblers-api/
Discussion:
Created cobbler tracking bugs for this issue:
Affects: epel-all [bug 1613293]
Affects: fedora-all [bug 1613292]
---
Statement:
The most sensitive function not requiring a valid token is modify_settings(), which is not part of cobbler-2.0.7, the versions shipped Red Hat Enterprise Satellite 5. As such, the flaw is considered with a Med
http://www.ibm.com/support/docview.wss?uid=ibm10875340http://www.securityfocus.com/bid/107435https://exchange.xforce.ibmcloud.com/vulnerabilities/152740http://www.ibm.com/support/docview.wss?uid=ibm10875340http://www.securityfocus.com/bid/107435https://exchange.xforce.ibmcloud.com/vulnerabilities/152740
2019-03-14
Published