CVE-2018-6495

EUVD-2018-18251
Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
microfocusCNA
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Affected Products (NVD)
VendorProductVersion
microfocusuniversal_cmdb
0.20
microfocusuniversal_cmdb
10.21
microfocusuniversal_cmdb
10.22
microfocusuniversal_cmdb
10.30
microfocusuniversal_cmdb
10.31
microfocusuniversal_cmdb
10.32
microfocusuniversal_cmdb
10.33
microfocusuniversal_cmdb
11.0
microfocusuniversal_cmdb_browser
4.10
microfocusuniversal_cmdb_browser
4.11
microfocusuniversal_cmdb_browser
4.12
microfocusuniversal_cmdb_browser
4.13
microfocusuniversal_cmdb_browser
4.14
microfocusuniversal_cmdb_browser
4.15.1
microfocuscms_server
4.10
microfocuscms_server
4.11
microfocuscms_server
4.12
microfocuscms_server
4.13
microfocuscms_server
4.14
microfocuscms_server
4.15.1
𝑥
= Vulnerable software versions