First published: Fri Sep 28 2018(Updated: )
RSA Authentication Manager versions prior to 8.3 P3 are affected by a DOM-based cross-site scripting vulnerability which exists in its embedded MadCap Flare Help files. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to the browser DOM, which code is then executed by the web browser in the context of the vulnerable web application.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
RSA Authentication Manager | <=8.3 | |
EMC RSA Authentication Manager | =8.3-p1 | |
EMC RSA Authentication Manager | =8.3-p2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11074 is a vulnerability affecting RSA Authentication Manager versions prior to 8.3 P3, which is a DOM-based cross-site scripting vulnerability existing in its embedded MadCap Flare Help files.
The severity of CVE-2018-11074 is medium, with a severity value of 6.1.
RSA Authentication Manager versions prior to 8.3 P3, EMC RSA Authentication Manager 8.3-p1, and EMC RSA Authentication Manager 8.3-p2 are affected.
A remote unauthenticated attacker could potentially exploit CVE-2018-11074 by tricking a victim application user into supplying malicious input.
Yes, you can find references for CVE-2018-11074 at the following links: [SecurityFocus](http://www.securityfocus.com/bid/105410), [SecurityTracker](http://www.securitytracker.com/id/1041697), [FullDisclosure](https://seclists.org/fulldisclosure/2018/Sep/39).