CVE-2018-2658
published 2018-01-18CVE-2018-2658: Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime SEC). The supported version that is…
PriorityP427medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
0.82%
53.6th percentile
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime SEC). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jd_edwards_enterpriseone_tools | — | — |
| oracle_corporation | jd_edwards_enterpriseone_tools | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-20821 libsass: parsing component allows attackers to cause denial-of-service
bugzilla·2019-05-03·CVSS 6.5
CVE-2018-20821 [MEDIUM] CVE-2018-20821 libsass: parsing component allows attackers to cause denial-of-service
CVE-2018-20821 libsass: parsing component allows attackers to cause denial-of-service
The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Parser::parse_css_variable_value in parser.cpp).
Reference:
https://github.com/sass/libsass/issues/2658
Discussion:
Created libsass tracking bugs for this issue:
Affects: fedora-all [bug 1706051]
---
Created libsass tracking bugs for this issue:
Affects: epel-7 [bug 1706052]
---
First vulnerable commit:
https://github.com/sass/libsass/commit/efd97dae376de50b3e6ed724337c4f274a21491d
---
Upstream patch:
https://github.com/sass/libsass/commit/f2db04883e5fff4e03777dcc1eb60d4373c45be1
---
Statement:
This issue did not affect the versions of libsass as shipped with Red Hat
Bugzilla
CVE-2018-18956 suricata: Segmentation fault in the ProcessMimeEntity function
bugzilla·2018-11-06·CVSS 7.5
CVE-2018-18956 [HIGH] CVE-2018-18956 suricata: Segmentation fault in the ProcessMimeEntity function
CVE-2018-18956 suricata: Segmentation fault in the ProcessMimeEntity function
The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x through 4.0.5 allows remote attackers to cause a denial of service (segfault and daemon crash) via crafted input to the SMTP parser.
References:
https://lists.openinfosecfoundation.org/pipermail/oisf-users/2018-October/016227.html
https://redmine.openinfosecfoundation.org/issues/2658#change-10374
Discussion:
Created suricata tracking bugs for this issue:
Affects: epel-7 [bug 1646984]
Affects: fedora-all [bug 1646983]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual communi
Bugzilla
CVE-2017-2658 Dashbuilder: Lack of clickjacking protection on the login page
bugzilla·2017-03-16·CVSS 2.6
CVE-2017-2658 [LOW] CVE-2017-2658 Dashbuilder: Lack of clickjacking protection on the login page
CVE-2017-2658 Dashbuilder: Lack of clickjacking protection on the login page
It was discovered that the Dashbuilder login page could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking).
Discussion:
Acknowledgments:
Name: Martin Weiler (Red Hat)
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.4.2
Via RHSA-2017:0557 https://rhn.redhat.com/errata/RHSA-2017-0557.html
---
This issue has been addressed in the following products:
Red Hat JBoss Data Virtualization
Via RHSA-2018:2243 https://access.redhat.com/errata/RHSA-2018:2243
2018-01-18
Published