Cross-site scripting in Axis - CVE-2018-8032

 

Cross-site scripting in Axis - CVE-2018-8032

Published: August 8, 2018 / Updated: August 9, 2018


Vulnerability identifier: #VU14296
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2018-8032
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists in the default servlet/services due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

Axis
IBM Integration Bus
IBM Cloud Pak for Business Automation
IBM Maximo Asset Management
IBM Maximo Application Suite
IBM App Connect Enterprise
Opensuse
Fedora
axis
System Storage Support for Microsoft Volume Shadow Copy Service and Virtual Disk Service (VSS)
IBM Cognos Analytics

How to mitigate CVE-2018-8032

Install update from vendor's website.

IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
axis - update to 1.4-35.fc27
System Storage Support for Microsoft Volume Shadow Copy Service and Virtual Disk Service (VSS) - update to 4.19.1.3
IBM Maximo Asset Management - addressed in versions 7.6.1.2.0.29, 7.6.1.3.0.4
IBM Maximo Application Suite - update to 8.4.5
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2

External References

Related Security Bulletins