CVE-2014-0638: XSS
Cross-site scripting (XSS) vulnerability in RSA Adaptive Authentication (On-Premise) 6.x and 7.x before 7.1 SP0 P2 allows remote attackers to inject arbitrary web script or HTML via vectors involving FRAME elements, related to a "cross-frame scripting" issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0638?
CVE-2014-0638 is categorized as a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2014-0638?
To fix CVE-2014-0638, update to RSA Adaptive Authentication (On-Premise) version 7.1 SP0 P2 or later.
What types of attacks can CVE-2014-0638 facilitate?
CVE-2014-0638 can facilitate cross-site scripting (XSS) attacks, enabling attackers to inject arbitrary web scripts or HTML.
Which versions of RSA Adaptive Authentication are affected by CVE-2014-0638?
CVE-2014-0638 affects RSA Adaptive Authentication (On-Premise) versions 6.x and 7.x prior to 7.1 SP0 P2.
Can CVE-2014-0638 be exploited without authentication?
Yes, CVE-2014-0638 can be exploited by remote attackers without requiring authentication.