CVE-2018-6495
Last modified
CVE-2018-6495 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microfocus | Universal Cmdb | 0.20 |
| Microfocus | Universal Cmdb | 10.21 |
| Microfocus | Universal Cmdb | 10.22 |
| Microfocus | Universal Cmdb | 10.30 |
| Microfocus | Universal Cmdb | 10.31 |
| Microfocus | Universal Cmdb | 10.32 |
| Microfocus | Universal Cmdb | 10.33 |
| Microfocus | Universal Cmdb | 11.0 |
| Microfocus | Universal Cmdb Browser | 4.10 |
| Microfocus | Universal Cmdb Browser | 4.11 |
| Microfocus | Universal Cmdb Browser | 4.12 |
| Microfocus | Universal Cmdb Browser | 4.13 |
| Microfocus | Universal Cmdb Browser | 4.14 |
| Microfocus | Universal Cmdb Browser | 4.15.1 |
| Microfocus | Cms Server | 4.10 |
| Microfocus | Cms Server | 4.11 |
| Microfocus | Cms Server | 4.12 |
| Microfocus | Cms Server | 4.13 |
| Microfocus | Cms Server | 4.14 |
| Microfocus | Cms Server | 4.15.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-6495?
How severe is CVE-2018-6495?
How do I fix CVE-2018-6495?
Are you affected by CVE-2018-6495?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
