Reflected Cross-Site Scripting Vulnerability
CVE-2018-1255

6.1MEDIUM

Key Information:

Vendor

Rsa

Vendor
CVE Published:
13 July 2018

What is CVE-2018-1255?

RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains a reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to a vulnerable web application, which is then reflected back to the victim and executed by the web browser.

Affected Version(s)

RSA Identity Governance and Lifecycle version 7.0.1, all patch levels

RSA Identity Governance and Lifecycle version 7.0.2, all patch levels

RSA Identity Governance and Lifecycle version 7.1.0, all patch levels

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.