CVE-2018-1483: XSS
Published Apr 11, 2018
·Updated
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140918.
Affected Software
19 affected components
IBM WebSphere Portal=8.5.0.0
IBM WebSphere Portal=8.5.0.0-cf1
IBM WebSphere Portal=8.5.0.0-cf10
IBM WebSphere Portal=8.5.0.0-cf11
IBM WebSphere Portal=8.5.0.0-cf12
IBM WebSphere Portal=8.5.0.0-cf13
IBM WebSphere Portal=8.5.0.0-cf14
IBM WebSphere Portal=8.5.0.0-cf15
IBM WebSphere Portal=8.5.0.0-cf2
IBM WebSphere Portal=8.5.0.0-cf3
IBM WebSphere Portal=8.5.0.0-cf4
IBM WebSphere Portal=8.5.0.0-cf5
IBM WebSphere Portal=8.5.0.0-cf6
IBM WebSphere Portal=8.5.0.0-cf7
IBM WebSphere Portal=8.5.0.0-cf8
IBM WebSphere Portal=8.5.0.0-cf9
IBM WebSphere Portal=9.0
IBM WebSphere Portal=9.0-cf14
IBM WebSphere Portal=9.0-cf15
Remediation
Patch Available
Event History
Apr 11, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1483?
CVE-2018-1483 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2018-1483?
To mitigate CVE-2018-1483, it is recommended to apply the latest patches provided by IBM for WebSphere Portal.
3
Which versions of IBM WebSphere Portal are affected by CVE-2018-1483?
CVE-2018-1483 affects IBM WebSphere Portal versions 8.5 and 9.0.
4
What type of vulnerability is CVE-2018-1483?
CVE-2018-1483 is a cross-site scripting (XSS) vulnerability.
5
What can an attacker do with CVE-2018-1483?
An attacker can exploit CVE-2018-1483 to inject arbitrary JavaScript code, potentially leading to credential disclosures.