PT-2018-2868 · Oracle · Oracle Secure Global Desktop

Rafael Pedrero

·

Publicado

2018-11-22

·

Atualizado

2019-01-07

·

CVE-2018-19439

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Oracle Secure Global Desktop versions prior to 5.4
Description The issue exists due to inadequate protection of the web page structure in the administration console. This can allow a remote attacker to execute arbitrary code in the user's browser or gain access to confidential information. The Administration Console in Oracle Secure Global Desktop is affected, with a specific example of reflected XSS via all parameters in the helpwindow.jsp page, such as the windowTitle parameter in the /sgdadmin/faces/com sun web ui/help/helpwindow.jsp endpoint.
Recommendations For Oracle Secure Global Desktop versions prior to 5.4, update to version 5.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the helpwindow.jsp page to minimize the risk of exploitation. Avoid using the vulnerable parameters, such as windowTitle, in the affected API endpoint until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02399
CVE-2018-19439

Produtos afetados

Oracle Secure Global Desktop