Cross-site scripting in AntiSamy - CVE-2024-23635

 

Cross-site scripting in AntiSamy - CVE-2024-23635

Published: February 22, 2024


Vulnerability identifier: #VU86736
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2024-23635
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data when parsing comment tags. A remote attacker can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of the vulnerability requires that the preserveComments directive is enabled in policy file.


Affected software

AntiSamy
Oracle Banking Party Management
IBM Maximo Asset Management
IBM Maximo Application Suite - Manage Component
Oracle Solaris Cluster
RSA Authentication Manager
Oracle Insurance Policy Administration
Oracle WebLogic Server

How to mitigate CVE-2024-23635

Install update from vendor's website.

AntiSamy - update to 1.7.5
RSA Authentication Manager - update to 8.7 SP2 Patch 6
IBM Maximo Asset Management - update to 7.6.1.3.19
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.13, 8.7.7

External References

Related Security Bulletins