CVE-2018-6958
published 2018-04-13CVE-2018-6958: VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitation of this…
PriorityP423medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.08%
61.6th percentile
VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitation of this issue may lead to the compromise of the vRA user's workstation.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vmware_vrealize | — | — |
| vmware | vrealize_automation | < 7.3.1 | 7.3.1 |
| vmware | vrealize_automation | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
vRealize Automation updates address multiple security issues.
vendor_vmware·2018-04-12·CVSS 6.1
CVE-2018-6958 [MEDIUM] vRealize Automation updates address multiple security issues.
VMSA-2018-0009: vRealize Automation updates address multiple security issues.
vRealize Automation (vRA) updates address multiple security issues. 2. Relevant Products vRealize Automation (vRA) 3. Problem Description a. DOM-based cross-site scripting (XSS) vulnerability. VMware vRealize Automation contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitation of this issue may lead to the compromise of the vRA user's workstation. VMware would like to thank Oliver Matula and Benjamin Schwendemann of ERNW Enno Rey Netzwerke GmbH for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2018-6958 to this issue. Column 5 of the following table lists the action required to remediate t
GHSA
GHSA-hvxm-j3vp-wx4q: VMware vRealize Automation (vRA) prior to 7
ghsa_unreviewed·2022-05-14
CVE-2018-6958 [MEDIUM] CWE-79 GHSA-hvxm-j3vp-wx4q: VMware vRealize Automation (vRA) prior to 7
VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitation of this issue may lead to the compromise of the vRA user's workstation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-04-13
Published