Cross-site scripting in Axis - CVE-2018-8032
Published: August 8, 2018 / Updated: August 9, 2018
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists in the default servlet/services due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
IBM Integration Bus
IBM Cloud Pak for Business Automation
IBM Maximo Asset Management
IBM Maximo Application Suite
IBM App Connect Enterprise
Opensuse
Fedora
axis
System Storage Support for Microsoft Volume Shadow Copy Service and Virtual Disk Service (VSS)
IBM Cognos Analytics
How to mitigate CVE-2018-8032
axis - update to 1.4-35.fc27
System Storage Support for Microsoft Volume Shadow Copy Service and Virtual Disk Service (VSS) - update to 4.19.1.3
IBM Maximo Asset Management - addressed in versions 7.6.1.2.0.29, 7.6.1.3.0.4
IBM Maximo Application Suite - update to 8.4.5
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
External References
Related Security Bulletins
- Cross-site scripting in Apache Axis
- OpenSUSE Linux update for axis
- Multiple vulnerabilities in IBM Maximo Asset Management and IBM Maximo Application Suite
- Multiple vulnerabilities in IBM App Connect Enterprise Toolkit and the IBM Integration Bus Toolkit
- Multiple vulnerabilities in IBM Cognos Analytics
- Fedora 27 update for axis
- Multiple vulnerabilities in IBM System Storage Support for Microsoft Volume Shadow Copy Service and Virtual Disk Service (VSS)
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation