PT-2018-2868 · Oracle · Oracle Secure Global Desktop
Rafael Pedrero
·
Publicado
2018-11-22
·
Atualizado
2019-01-07
·
CVE-2018-19439
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Secure Global Desktop versions prior to 5.4
Description
The issue exists due to inadequate protection of the web page structure in the administration console. This can allow a remote attacker to execute arbitrary code in the user's browser or gain access to confidential information. The Administration Console in Oracle Secure Global Desktop is affected, with a specific example of reflected XSS via all parameters in the helpwindow.jsp page, such as the
windowTitle parameter in the /sgdadmin/faces/com sun web ui/help/helpwindow.jsp endpoint.Recommendations
For Oracle Secure Global Desktop versions prior to 5.4, update to version 5.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the helpwindow.jsp page to minimize the risk of exploitation. Avoid using the vulnerable parameters, such as
windowTitle, in the affected API endpoint until the issue is resolved.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Oracle Secure Global Desktop