CVE-2018-6189: XSS
Published Feb 16, 2018
·Updated
F-Secure Radar (on-premises) before 2018-02-15 has XSS via vectors involving the Tags parameter in the JSON request body in an outbound request for the /api/latest/vulnerabilityscans/tags/batch resource, aka a "suggested metadata tags for assets" issue.
Affected Software
1 affected component
F-Secure Radar<=3.9.1
Event History
Feb 16, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Data Sourced
via NVD·04:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6189?
CVE-2018-6189 is considered a medium severity vulnerability due to its potential for exploitation via cross-site scripting.
2
How do I fix CVE-2018-6189?
To mitigate CVE-2018-6189, upgrade F-Secure Radar to version 3.9.2 or later.
3
What kind of vulnerability is CVE-2018-6189?
CVE-2018-6189 is a Cross-Site Scripting (XSS) vulnerability affecting F-Secure Radar.
4
Which versions of F-Secure Radar are affected by CVE-2018-6189?
F-Secure Radar versions before 3.9.2 are affected by CVE-2018-6189.
5
What is the attack vector for CVE-2018-6189?
CVE-2018-6189 can be exploited through malicious vectors involving the Tags parameter in JSON requests.