CVE-2018-6496
MFSBGN03809 rev.1 - Universal CMDB, Deserialization Java Objects and CSRF
Severity Score
8.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).
Se ha identificado potencial para Cross-Site Request Forgery (CSRF) remoto en UCMBD Browser, en sus versiones 4.10, 4.11, 4.12, 4.13, 4.14, 4.15 y 4.15.1 que podrÃa permitir la deserialización remota no segura y Cross-Site Request Forgery (CSRF).
*Credits:
Micro Focus would like to thank Mateusz Garncarek for reporting this issue to cyber-psrt@microfocus.com.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2018-02-01 CVE Reserved
- 2018-06-15 CVE Published
- 2023-11-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/104483 | Vdb Entry | |
http://www.securitytracker.com/id/1041139 | Vdb Entry | |
https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03180066 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microfocus Search vendor "Microfocus" | Universal Cmbd Browser Search vendor "Microfocus" for product "Universal Cmbd Browser" | >= 4.10 <= 4.15.1 Search vendor "Microfocus" for product "Universal Cmbd Browser" and version " >= 4.10 <= 4.15.1" | - |
Affected
|