// For flags

CVE-2018-1660

 

Severity Score

5.4
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 144886.

IBM WebSphere Portal 7.0, 8.0, 8.5 y 9.0 es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. Esto podría dar lugar a una revelación de credenciales en una sesión de confianza. IBM X-Force ID: 144886.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-12-13 CVE Reserved
  • 2018-09-27 CVE Published
  • 2024-05-14 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.0"
-
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
-
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf002
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf003
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf004
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf005
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf006
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf007
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf008
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf009
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf010
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf011
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf012
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf013
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf014
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf015
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf016
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf017
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf018
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf019
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.1"
cf020
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
-
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf011
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf012
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf013
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf014
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf015
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf016
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf017
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf018
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf019
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf020
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf021
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf022
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf023
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf024
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf025
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf026
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf027
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf028
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf029
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
7.0.0.2
Search vendor "Ibm" for product "Websphere Portal" and version "7.0.0.2"
cf030
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.0"
-
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.0"
cf01
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.0"
cf02
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.0"
cf03
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.0"
cf04
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.0"
cf05
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.0"
cf06
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
-
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf04
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf05
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf06
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf07
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf08
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf09
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf10
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf11
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf12
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf13
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf14
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf15
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf16
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf17
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf18
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf19
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf20
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf21
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf22
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.0.0.1
Search vendor "Ibm" for product "Websphere Portal" and version "8.0.0.1"
cf23
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.5.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.5.0.0"
-
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.5.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.5.0.0"
cf01
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.5.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.5.0.0"
cf02
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.5.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.5.0.0"
cf03
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.5.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.5.0.0"
cf04
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.5.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.5.0.0"
cf05
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.5.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.5.0.0"
cf06
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.5.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.5.0.0"
cf07
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.5.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.5.0.0"
cf08
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.5.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.5.0.0"
cf09
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.5.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.5.0.0"
cf10
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.5.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.5.0.0"
cf11
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.5.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.5.0.0"
cf12
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.5.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.5.0.0"
cf13
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.5.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.5.0.0"
cf14
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
8.5.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "8.5.0.0"
cf15
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
9.0.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "9.0.0.0"
-
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
9.0.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "9.0.0.0"
cf14
Affected
Ibm
Search vendor "Ibm"
Websphere Portal
Search vendor "Ibm" for product "Websphere Portal"
9.0.0.0
Search vendor "Ibm" for product "Websphere Portal" and version "9.0.0.0"
cf15
Affected