First published: Fri Apr 13 2018(Updated: )
VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitation of this issue may lead to the compromise of the vRA user's workstation.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vRealize Automation | <7.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6958 is a vulnerability in VMware vRealize Automation (vRA) prior to 7.3.1 that allows for a DOM-based cross-site scripting (XSS) attack.
The severity of CVE-2018-6958 is medium with a CVSS score of 6.1.
The vulnerability in CVE-2018-6958 may lead to the compromise of the vRA user's workstation.
To address the vulnerability in CVE-2018-6958, it is recommended to upgrade to VMware vRealize Automation 7.3.1 or later.
You can find more information about CVE-2018-6958 at the following references: [Link 1](http://www.securityfocus.com/bid/103752), [Link 2](http://www.securitytracker.com/id/1040676), [Link 3](http://www.vmware.com/security/advisories/VMSA-2018-0009.html).