ID

VAR-201801-1852


TITLE

Cross-site Scripting Vulnerability in Fujitsu Interstage List Works

Trust: 0.8

sources: JVNDB: JVNDB-2017-004687

DESCRIPTION

A cross-suite scripting vulnerability has been found in web functionality of Fujitsu Interstage List Works.By creating a malicious webpage that exploits this vulnerability, an attacker could execute arbitrary code on the user's computer used to access the malicious webpage.

Trust: 0.8

sources: JVNDB: JVNDB-2017-004687

AFFECTED PRODUCTS

vendor:fujitsumodel:interstage list worksscope:eqversion:enterprise edition

Trust: 0.8

vendor:fujitsumodel:interstage list worksscope:eqversion:standard edition

Trust: 0.8

sources: JVNDB: JVNDB-2017-004687

CVSS

SEVERITY

CVSSV2

CVSSV3

IPA: JVNDB-2017-004687
value: MEDIUM

Trust: 0.8

IPA: JVNDB-2017-004687
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

IPA: JVNDB-2017-004687
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2017-004687

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 0.8

sources: JVNDB: JVNDB-2017-004687

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-004687

PATCH

title:interstage-lw-201701url:http://www.fujitsu.com/jp/products/software/resources/condition/security/products-fujitsu/solution/interstage-lw-201701.html

Trust: 0.8

sources: JVNDB: JVNDB-2017-004687

EXTERNAL IDS

db:JVNDBid:JVNDB-2017-004687

Trust: 0.8

sources: JVNDB: JVNDB-2017-004687

SOURCES

db:JVNDBid:JVNDB-2017-004687

LAST UPDATE DATE

2022-05-04T09:17:10.276000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2017-004687date:2018-01-12T00:00:00

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2017-004687date:2018-01-12T00:00:00