First published: Thu Jun 21 2018(Updated: )
Micro Focus Solutions Business Manager versions prior to 11.4 allows JavaScript to be embedded in URLs placed in "Favorites" folder. If the user has certain administrative privileges then this vulnerability can impact other users in the system.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus Solutions Business Manager | <11.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7681 has been classified as a medium severity vulnerability due to its potential impact on users with administrative privileges.
To fix CVE-2018-7681, upgrade to Micro Focus Solutions Business Manager version 11.4 or later.
CVE-2018-7681 affects all versions of Micro Focus Solutions Business Manager prior to 11.4.
CVE-2018-7681 can allow an attacker with certain administrative privileges to execute JavaScript through embedded URLs in user favorites.
Currently, there is no official workaround for CVE-2018-7681, so upgrading to the latest version is strongly recommended.