CVE-2018-10934 PUBLISHED CVSS 5.400000095367432 MEDIUM

A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.

EPSS 0.41% · 61.4th percentile

Risk Scores

CVSS v3.0
5.400000095367432
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.41%
61.4th percentile

Affected Products

VendorProductVersions
redhatjboss_enterprise_application_platform7.0, 7.1.0
Red Hatwildfly-core7.1.6.CR1, 7.1.6.GA
redhatsingle_sign-on7.2

Timeline

References

Open in Interactive Console →