First published: Mon Jul 09 2018(Updated: )
A reflected Cross-Site-Scripting (XSS) vulnerability has been identified in Siemens PLM Software TEAMCENTER (V9.1.2.5). If a user visits the login portal through the URL crafted by the attacker, the attacker can insert html/javascript and thus alter/rewrite the login portal page. Siemens PLM Software TEAMCENTER V9.1.3 and newer are not affected.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Teamcenter | <=9.1.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11450 is classified as a high severity vulnerability due to its potential for reflected Cross-Site Scripting (XSS) attacks.
To fix CVE-2018-11450, it is recommended to upgrade Siemens Teamcenter to a version above 9.1.2.5 that addresses this vulnerability.
CVE-2018-11450 allows attackers to alter the login portal page, potentially leading to phishing or credential theft.
CVE-2018-11450 specifically affects Siemens Teamcenter versions up to and including 9.1.2.5.
Any organization utilizing Siemens Teamcenter version 9.1.2.5 or earlier is vulnerable to CVE-2018-11450.