CVE-2018-1812
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
IBM Robotic Process Automation with Automation Anywhere Enterprise 10 is vulnerable to persistent cross-site scripting, caused by missing escaping of a database field. An attacker that has access to the Control Room database could exploit this vulnerability to execute script in a victim's web browser within the security context of the hosting Web site, once victim opens a certain page in Control Room. IBM X-Force ID: 149883.
IBM Robotic Process Automation with Automation Anywhere Enterprise 10 es vulnerable a Cross-Site Scripting (XSS) persistente provocado por la falta de escape del campo de una base de datos. Un atacante que tenga acceso a la base de datos Control Room podría explotar esta vulnerabilidad para ejecutar scripts en el navegador web de una víctima en el contexto de seguridad del sitio web alojador, una vez la víctima abre cierta página en Control Room. IBM X-Force ID: 149883.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-13 CVE Reserved
- 2018-10-05 CVE Published
- 2024-08-11 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.ibm.com/support/docview.wss?uid=ibm10731925 | 2019-10-09 |
URL | Date | SRC |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/149883 | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Robotic Process Automation With Automation Anywhere Search vendor "Ibm" for product "Robotic Process Automation With Automation Anywhere" | 10.0 Search vendor "Ibm" for product "Robotic Process Automation With Automation Anywhere" and version "10.0" | - |
Affected
|