{"containers":{"cna":{"affected":[{"product":"Authentication Manager","vendor":"RSA","versions":[{"lessThan":"8.3 P1","status":"affected","version":"unspecified","versionType":"custom"}]}],"datePublic":"2018-06-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulnerability. A malicious Operations Console administrator could potentially exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console administrators open the affected page, the injected scripts could potentially be executed in their browser."}],"metrics":[{"cvssV3_0":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L","version":"3.0"}}],"problemTypes":[{"descriptions":[{"description":"xss vulnerability","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-06-26T09:57:02.000Z","orgId":"c550e75a-17ff-4988-97f0-544cde3820fe","shortName":"dell"},"references":[{"name":"104534","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/104534"},{"name":"1041134","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1041134"},{"name":"20180612 DSA-2018-107: RSA Authentication Manager Cross-site scripting Vulnerabilities","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://seclists.org/fulldisclosure/2018/Jun/39"}],"source":{"discovery":"UNKNOWN"},"title":"Stored cross-site scripting vulnerability","x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security_alert@emc.com","DATE_PUBLIC":"2018-06-12T05:00:00.000Z","ID":"CVE-2018-1253","STATE":"PUBLIC","TITLE":"Stored cross-site scripting vulnerability"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Authentication Manager","version":{"version_data":[{"affected":"<","version_affected":"<","version_value":"8.3 P1"}]}}]},"vendor_name":"RSA"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulnerability. A malicious Operations Console administrator could potentially exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console administrators open the affected page, the injected scripts could potentially be executed in their browser."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L","version":"3.0"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"xss vulnerability"}]}]},"references":{"reference_data":[{"name":"104534","refsource":"BID","url":"http://www.securityfocus.com/bid/104534"},{"name":"1041134","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1041134"},{"name":"20180612 DSA-2018-107: RSA Authentication Manager Cross-site scripting Vulnerabilities","refsource":"FULLDISC","url":"http://seclists.org/fulldisclosure/2018/Jun/39"}]},"source":{"discovery":"UNKNOWN"}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-05T03:51:49.056Z"},"title":"CVE Program Container","references":[{"name":"104534","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/104534"},{"name":"1041134","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1041134"},{"name":"20180612 DSA-2018-107: RSA Authentication Manager Cross-site scripting Vulnerabilities","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2018/Jun/39"}]}]},"cveMetadata":{"assignerOrgId":"c550e75a-17ff-4988-97f0-544cde3820fe","assignerShortName":"dell","cveId":"CVE-2018-1253","datePublished":"2018-06-21T15:00:00.000Z","dateReserved":"2017-12-06T00:00:00.000Z","dateUpdated":"2024-09-17T03:52:50.534Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}