ZeroHour

CVE-2018-1461

CVSS 3.1
5.4 medium
EPSS
<1%p60
Published
()
Modified
Description

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140362.

Vendors
ibm
Products
storwize v7000 firmware, storwize v5000 firmware, storwize v3700 firmware, storwize v3500 firmware, storwize v9000 firmware, san volume controller firmware, spectrum virtualize, spectrum virtualize for public cloud
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.