CVE-2018-1889: XSS
IBM Security Guardium 10.0 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152080.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1889?
The severity of CVE-2018-1889 is classified as medium due to its potential for JavaScript injection and credential disclosure.
How do I fix CVE-2018-1889?
To fix CVE-2018-1889, upgrade IBM Security Guardium to version 10.6 or later, which contains the necessary patches to mitigate the vulnerability.
What versions of IBM Security Guardium are affected by CVE-2018-1889?
IBM Security Guardium versions 10.0 and 10.5 are affected by CVE-2018-1889.
What kind of attacks can CVE-2018-1889 enable?
CVE-2018-1889 enables cross-site scripting attacks that can lead to malicious JavaScript execution and possibly credential disclosure.
Is CVE-2018-1889 a client-side or server-side vulnerability?
CVE-2018-1889 is primarily a client-side vulnerability that affects the Web UI of IBM Security Guardium.