CVE-2018-19439: XSS
XSS exists in the Administration Console in Oracle Secure Global Desktop 4.4 20080807152602 (but was fixed in later versions including 5.4). helpwindow.jsp has reflected XSS via all parameters, as demonstrated by the sgdadmin/faces/comsunwebui/help/helpwindow.jsp windowTitle parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19439?
CVE-2018-19439 is a vulnerability in the Administration Console in Oracle Secure Global Desktop 4.4 20080807152602 (but was fixed in later versions including 5.4).
What is the severity of CVE-2018-19439?
The severity of CVE-2018-19439 is medium with a severity value of 6.1.
How does CVE-2018-19439 affect Oracle Secure Global Desktop?
CVE-2018-19439 affects Oracle Secure Global Desktop version 4.4.
What is the impact of CVE-2018-19439?
The impact of CVE-2018-19439 is the possibility of reflected cross-site scripting (XSS) attacks via all parameters in the helpwindow.jsp page.
How do I fix CVE-2018-19439?
To fix CVE-2018-19439, upgrade Oracle Secure Global Desktop to a version later than 5.4.