First published: Tue Apr 17 2018(Updated: )
IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139907.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | >=8.0.0.0<=8.0.0.1 | |
IBM WebSphere Portal | =8.5 | |
IBM WebSphere Portal | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1445 has a medium severity rating that indicates a moderate risk based on its impact and exploitability.
To fix CVE-2018-1445, users should apply the latest patches and updates provided by IBM for affected versions of WebSphere Portal.
CVE-2018-1445 affects IBM WebSphere Portal versions 8.0.0 through 8.0.0.1, 8.5, and 9.0.
CVE-2018-1445 allows for cross-site scripting attacks, potentially leading to the disclosure of sensitive information like user credentials.
While applying updates is the recommended fix, users should also review and modify web application settings to limit exposure to cross-site scripting.