CVE-2018-1777: XSS
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148800.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1777?
CVE-2018-1777 is classified as a moderate severity cross-site scripting vulnerability.
How do I fix CVE-2018-1777?
To fix CVE-2018-1777, upgrade IBM WebSphere Application Server to a version above the affected versions that contain the security patch.
What versions are affected by CVE-2018-1777?
CVE-2018-1777 affects IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0 up to specific patch levels.
What kind of attack can be executed due to CVE-2018-1777?
CVE-2018-1777 allows attackers to execute arbitrary JavaScript code, potentially leading to credential disclosure within trusted sessions.
Is user interaction required to exploit CVE-2018-1777?
Yes, exploiting CVE-2018-1777 typically requires user interaction to execute the embedded JavaScript code.