Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:*:*:*:*:*:*:*:*", "matchCriteriaId": "F38C843F-4D75-4DC4-BCE2-AC94EA2AADFA", "versionEndIncluding": "7.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:7.1:-:*:*:*:*:*:*", "matchCriteriaId": "8DB84FE8-27E3-4B6A-9F7B-B3852FD973B2", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:7.1:sp2:*:*:*:*:*:*", "matchCriteriaId": "CFEA20F9-BFEA-4599-91B8-51F2C62257B1", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:7.1:sp3:*:*:*:*:*:*", "matchCriteriaId": "276F775A-7622-46C1-AFAB-BAD4ADB4F551", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:7.1:sp4:*:*:*:*:*:*", "matchCriteriaId": "28238983-F94B-4EC7-AE15-4E6B6110DC19", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.0:-:*:*:*:*:*:*", "matchCriteriaId": "5D880442-0B4A-4D54-9E98-6091B59BC9F1", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.0:p1:*:*:*:*:*:*", "matchCriteriaId": "008D1316-B493-42D2-8A28-FDB935B4DCE3", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.1:-:*:*:*:*:*:*", "matchCriteriaId": "D5CEBCC8-C970-420B-9C32-2CD233461486", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.1:sp1:*:*:*:*:*:*", "matchCriteriaId": "AC7D1E9E-3BAE-4FD2-B69F-0013065F0744", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.2:-:*:*:*:*:*:*", "matchCriteriaId": "0E662A19-3595-4E54-B6FA-C387E1B5FBA6", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1:*:*:*:*:*:*", "matchCriteriaId": "7A3C063C-76E1-443A-8BAE-FFC9C66DE925", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.3:-:*:*:*:*:*:*", "matchCriteriaId": "29A8B165-32AE-42CC-BE85-CEEF25C8F27A", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.3:p1:*:*:*:*:*:*", "matchCriteriaId": "C55F4F6D-FFE4-4D14-9481-DC8D52B6EDFE", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "descriptions": [{"lang": "en", "value": "RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulnerability. A malicious Operations Console administrator could potentially exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console administrators open the affected page, the injected scripts could potentially be executed in their browser."}, {"lang": "es", "value": "RSA Authentication Manager Operation Console, en versiones 8.3 P1 y anteriores, contiene una vulnerabilidad de Cross-Site Scripting (XSS) persistente. Un administrador de Operations Console podr\u00eda explotar esta vulnerabilidad para almacenar c\u00f3digo HTML o JavaScript arbitrario mediante la interfaz web. Cuando otros administradores Operations Console abren la p\u00e1gina afectada, los scripts inyectados pueden ejecutarse en sus navegadores."}], "id": "CVE-2018-1253", "lastModified": "2024-11-21T03:59:28.303", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": {"accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "version": "2.0"}, "exploitabilityScore": 8.6, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true}], "cvssMetricV30": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "LOW", "scope": "CHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L", "version": "3.0"}, "exploitabilityScore": 2.3, "impactScore": 3.7, "source": "security_alert@emc.com", "type": "Secondary"}], "cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.1, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "NONE", "scope": "CHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "version": "3.1"}, "exploitabilityScore": 2.8, "impactScore": 2.7, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2018-06-21T15:29:00.270", "references": [{"source": "security_alert@emc.com", "tags": ["Mailing List", "Third Party Advisory"], "url": "http://seclists.org/fulldisclosure/2018/Jun/39"}, {"source": "security_alert@emc.com", "tags": ["Third Party Advisory", "VDB Entry"], "url": "http://www.securityfocus.com/bid/104534"}, {"source": "security_alert@emc.com", "tags": ["Third Party Advisory", "VDB Entry"], "url": "http://www.securitytracker.com/id/1041134"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Mailing List", "Third Party Advisory"], "url": "http://seclists.org/fulldisclosure/2018/Jun/39"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Third Party Advisory", "VDB Entry"], "url": "http://www.securityfocus.com/bid/104534"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Third Party Advisory", "VDB Entry"], "url": "http://www.securitytracker.com/id/1041134"}], "sourceIdentifier": "security_alert@emc.com", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-79"}], "source": "nvd@nist.gov", "type": "Primary"}]}