« Volver al listado

CVE-2018-1253

Estado: ModificadaMedia (6.1)—

RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulnerability. A malicious Operations Console administrator could potentially exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console administrators open the affected page, the injected scripts could potentially be executed in their browser.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-1253",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.7,
        "exploitabilityScore": 2.3
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "RSA",
          "product": "Authentication Manager",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "8.3 P1",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-06-21T15:29:00.270",
  "references": [
    {
      "url": "http://seclists.org/fulldisclosure/2018/Jun/39",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/104534",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1041134",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2018/Jun/39",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/104534",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1041134",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulnerability. A malicious Operations Console administrator could potentially exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console administrators open the affected page, the injected scripts could potentially be executed in their browser."
    },
    {
      "lang": "es",
      "value": "RSA Authentication Manager Operation Console, en versiones 8.3 P1 y anteriores, contiene una vulnerabilidad de Cross-Site Scripting (XSS) persistente. Un administrador de Operations Console podría explotar esta vulnerabilidad para almacenar código HTML o JavaScript arbitrario mediante la interfaz web. Cuando otros administradores Operations Console abren la página afectada, los scripts inyectados pueden ejecutarse en sus navegadores."
    }
  ],
  "lastModified": "2026-06-17T01:50:49.453",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F38C843F-4D75-4DC4-BCE2-AC94EA2AADFA",
              "versionEndIncluding": "7.0"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:7.1:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8DB84FE8-27E3-4B6A-9F7B-B3852FD973B2"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:7.1:sp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFEA20F9-BFEA-4599-91B8-51F2C62257B1"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:7.1:sp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "276F775A-7622-46C1-AFAB-BAD4ADB4F551"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:7.1:sp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28238983-F94B-4EC7-AE15-4E6B6110DC19"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D880442-0B4A-4D54-9E98-6091B59BC9F1"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.0:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "008D1316-B493-42D2-8A28-FDB935B4DCE3"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.1:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5CEBCC8-C970-420B-9C32-2CD233461486"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.1:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC7D1E9E-3BAE-4FD2-B69F-0013065F0744"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.2:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E662A19-3595-4E54-B6FA-C387E1B5FBA6"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A3C063C-76E1-443A-8BAE-FFC9C66DE925"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.3:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29A8B165-32AE-42CC-BE85-CEEF25C8F27A"
            },
            {
              "criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.3:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C55F4F6D-FFE4-4D14-9481-DC8D52B6EDFE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}