Tridium Niagara Enterprise Security 2.3u1, all versions prior to 2.3.118.6, Niagara AX 3.8u4, all versions prior to 3.8.401.1, Niagara 4.4u2, all versions prior to 4.4.93.40.2, and Niagara 4.6, all versions prior to 4.6.96.28.4 a cross-site scripting vulnerability has been identified that may allow a remote attacker to inject code to some web pages affecting confidentiality.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/106530 | Third Party Advisory VDB Entry |
https://ics-cert.us-cert.gov/advisories/ICSA-18-333-02 | Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/106530 | Third Party Advisory VDB Entry |
https://ics-cert.us-cert.gov/advisories/ICSA-18-333-02 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:56
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/106530 - Third Party Advisory, VDB Entry | |
References | () https://ics-cert.us-cert.gov/advisories/ICSA-18-333-02 - Third Party Advisory, US Government Resource |
Information
Published : 2019-01-29 16:29
Updated : 2024-11-21 03:56
NVD link : CVE-2018-18985
Mitre link : CVE-2018-18985
CVE.ORG link : CVE-2018-18985
JSON object : View
Products Affected
tridium
- niagara
- niagara_enterprise_security
- niagara_ax_framework
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')