CVE-2018-6496: MFSBGN03809 rev.1 - Universal CMDB, Deserialization Java Objects and CSRF
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Universal CMDB UCMBD Browserto a version that resolves this vulnerability.Fixed in 4.10 - Upgrade
Upgrade
Universal CMDB UCMBD Browserto a version that resolves this vulnerability.Fixed in 4.11 - Upgrade
Upgrade
Universal CMDB UCMBD Browserto a version that resolves this vulnerability.Fixed in 4.12 - Upgrade
Upgrade
Universal CMDB UCMBD Browserto a version that resolves this vulnerability.Fixed in 4.13 - Upgrade
Upgrade
Universal CMDB UCMBD Browserto a version that resolves this vulnerability.Fixed in 4.14 - Upgrade
Upgrade
Universal CMDB UCMBD Browserto a version that resolves this vulnerability.Fixed in 4.15 - Upgrade
Upgrade
Universal CMDB UCMBD Browserto a version that resolves this vulnerability.Fixed in 4.15.1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6496?
CVE-2018-6496 is rated as a medium severity vulnerability.
How do I fix CVE-2018-6496?
To fix CVE-2018-6496, upgrade to a version of Microfocus Universal Cmbd Browser later than 4.15.1.
What types of attacks can CVE-2018-6496 enable?
CVE-2018-6496 can potentially enable remote unsafe deserialization and cross-site request forgery (CSRF) attacks.
Which versions of Microfocus Universal Cmbd Browser are affected by CVE-2018-6496?
CVE-2018-6496 affects versions 4.10 through 4.15.1 of the Microfocus Universal Cmbd Browser.
Is CVE-2018-6496 a remote vulnerability?
Yes, CVE-2018-6496 is a remote vulnerability that can be exploited by a malicious actor.