Improper Neutralization of Special Elements in Output Used by a Downstream Component in Debian Linux - CVE-2018-15494

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Debian Linux - CVE-2018-15494

Published: August 18, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU36773
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15494
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.


Affected software

Debian Linux
Ubuntu
Log Analysis
IBM Security Guardium Key Lifecycle Manager (GKLM)
WebSphere eXtreme Scale
Financial Transaction Manager for ACH Services and Check Services
IBM Sterling B2B Integrator
IBM Security Verify Governance
IBM Cloud Pak for Business Automation
IBM Cloud Pak System
IBM Tivoli Network Manager (ITNM)
Tivoli Network Manager IP Edition
dojo (Ubuntu package)
IBM Security Identity Manager
IBM Qradar SIEM

How to mitigate CVE-2018-15494

Install update from vendor's website.

IBM Cloud Pak System - update to 2.3.3.6
IBM Security Guardium Key Lifecycle Manager (GKLM) - update to 4.1.1 FP6
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.15
Tivoli Network Manager IP Edition - update to 4.2.0.20
WebSphere eXtreme Scale - update to 8.6.1.5 PH53340
dojo (Ubuntu package) - addressed in versions 1.10.4+dfsg-2ubuntu0.1~esm1, 1.15.0+dfsg1-1ubuntu0.1~esm1, 1.15.4+dfsg1-1ubuntu0.1
Financial Transaction Manager for ACH Services and Check Services - update to 3.0.5.4 iFix 28
IBM Security Identity Manager - addressed in versions 6.0.0 FP0027, 6.0.2 FP0005
IBM Sterling B2B Integrator - update to 6.1.2.2
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
IBM Security Verify Governance - update to 10.0.2.0.3
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003

External References

Related Security Bulletins