CVE-2018-7681: XSS
Micro Focus Solutions Business Manager versions prior to 11.4 allows JavaScript to be embedded in URLs placed in "Favorites" folder. If the user has certain administrative privileges then this vulnerability can impact other users in the system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Micro Focus Solutions Business Managerto a version that resolves this vulnerability.Fixed in 11.4
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7681?
CVE-2018-7681 has been classified as a medium severity vulnerability due to its potential impact on users with administrative privileges.
How do I fix CVE-2018-7681?
To fix CVE-2018-7681, upgrade to Micro Focus Solutions Business Manager version 11.4 or later.
What systems are affected by CVE-2018-7681?
CVE-2018-7681 affects all versions of Micro Focus Solutions Business Manager prior to 11.4.
What is the impact of CVE-2018-7681 on users?
CVE-2018-7681 can allow an attacker with certain administrative privileges to execute JavaScript through embedded URLs in user favorites.
Is there a workaround for CVE-2018-7681?
Currently, there is no official workaround for CVE-2018-7681, so upgrading to the latest version is strongly recommended.