CVE-2018-6958: XSS
VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitation of this issue may lead to the compromise of the vRA user's workstation.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-6958?
CVE-2018-6958 is a vulnerability in VMware vRealize Automation (vRA) prior to 7.3.1 that allows for a DOM-based cross-site scripting (XSS) attack.
What is the severity of CVE-2018-6958?
The severity of CVE-2018-6958 is medium with a CVSS score of 6.1.
How does CVE-2018-6958 impact VMware vRealize Automation (vRA) users?
The vulnerability in CVE-2018-6958 may lead to the compromise of the vRA user's workstation.
How can I fix CVE-2018-6958?
To address the vulnerability in CVE-2018-6958, it is recommended to upgrade to VMware vRealize Automation 7.3.1 or later.
Where can I find more information about CVE-2018-6958?
You can find more information about CVE-2018-6958 at the following references: [Link 1](http://www.securityfocus.com/bid/103752), [Link 2](http://www.securitytracker.com/id/1040676), [Link 3](http://www.vmware.com/security/advisories/VMSA-2018-0009.html).