CVE-2018-11074: DSA-2018-152: RSA® Authentication Manager Multiple Vulnerabilities
RSA Authentication Manager versions prior to 8.3 P3 are affected by a DOM-based cross-site scripting vulnerability which exists in its embedded MadCap Flare Help files. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to the browser DOM, which code is then executed by the web browser in the context of the vulnerable web application.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11074?
CVE-2018-11074 is a vulnerability affecting RSA Authentication Manager versions prior to 8.3 P3, which is a DOM-based cross-site scripting vulnerability existing in its embedded MadCap Flare Help files.
How severe is the CVE-2018-11074 vulnerability?
The severity of CVE-2018-11074 is medium, with a severity value of 6.1.
Which software versions are affected by CVE-2018-11074?
RSA Authentication Manager versions prior to 8.3 P3, EMC RSA Authentication Manager 8.3-p1, and EMC RSA Authentication Manager 8.3-p2 are affected.
How can an attacker exploit CVE-2018-11074?
A remote unauthenticated attacker could potentially exploit CVE-2018-11074 by tricking a victim application user into supplying malicious input.
Are there any references for CVE-2018-11074?
Yes, you can find references for CVE-2018-11074 at the following links: [SecurityFocus](http://www.securityfocus.com/bid/105410), [SecurityTracker](http://www.securitytracker.com/id/1041697), [FullDisclosure](https://seclists.org/fulldisclosure/2018/Sep/39).