CVE-2018-8900:CVE-2018-8900: Cross-site scripting (XSS) vulnerability in the License Manager service of HASP SRM, Sentinel HASP and Sentinel LDK prior to Sentinel LDK RTE 7.80, enabling remote attackers to inject malicious scripts via the Admin Control Center (ACC) logs page.

splash
Back

Description Preview

The License Manager service used by HASP SRM, Sentinel HASP, and Sentinel LDK products released before Sentinel LDK RTE 7.80 contains an XSS vulnerability in the Admin Control Center logs page. The input on that page is not adequately sanitized, allowing remote attackers to inject and execute arbitrary JavaScript when an administrator views the logs. This issue was publicly disclosed in 2018, and a fix is provided in Sentinel LDK RTE 7.80 and later. References to the vendor advisory SSA-566773 and related materials detail the vulnerability and its remediation.

Overview

This CVE documents a cross-site scripting vulnerability in the License Manager service used by HASP SRM, Sentinel HASP, and Sentinel LDK products. Prior to Sentinel LDK RTE 7.80, the logs page of Admin Control Center did not properly sanitize user-supplied input, enabling remote attackers to inject and execute malicious web script. The vulnerability was disclosed in 2018 and is tracked as CVE-2018-8900, with remediation available via upgrading to RTE 7.80 or newer per vendor advisories.

Remediation

  • Upgrade to Sentinel LDK RTE 7.80 or later (preferred fix).
  • Apply the vendor patch/ advisory SSA-566773 to mitigate the issue.
  • If upgrading is not feasible, implement compensating controls:
    • Restrict network access to the Admin Control Center and License Manager logs page to trusted administrators (e.g., via ACLs, VPN, or network segmentation).
    • Deploy a Web Application Firewall (WAF) or equivalent that blocks or sanitizes reflected input on the ACC logs page.
    • Disable or limit remote web access to ACC where possible; ensure least-privilege access to the management interface.
    • Enforce input validation/sanitization on any interfaces that render user-supplied data in the logs page if customization is possible.
    • Review and rotate administrator credentials; enable multifactor authentication if available.
  • After applying fixes, verify the remediation in a controlled test environment to ensure XSS vectors no longer execute.

References

Industry ExposureMost to least
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.

  1. Other Services (except Public Administration): Low
    Other Services (except Public Administration)
  2. Accommodation & Food Services: Low
    Accommodation & Food Services
  3. Administrative, Support, Waste Management & Remediation Services: Low
    Administrative, Support, Waste Management & Remediation Services
  4. Agriculture, Forestry Fishing & Hunting: Low
    Agriculture, Forestry Fishing & Hunting
  5. Arts, Entertainment & Recreation: Low
    Arts, Entertainment & Recreation
  6. Construction: Low
    Construction
  7. Educational Services: Low
    Educational Services
  8. Finance and Insurance: Low
    Finance and Insurance
  9. Health Care & Social Assistance: Low
    Health Care & Social Assistance
  10. Information: Low
    Information
  11. Management of Companies & Enterprises: Low
    Management of Companies & Enterprises
  12. Manufacturing: Low
    Manufacturing
  13. Mining: Low
    Mining
  14. Professional, Scientific, & Technical Services: Low
    Professional, Scientific, & Technical Services
  15. Public Administration: Low
    Public Administration
  16. Real Estate Rental & Leasing: Low
    Real Estate Rental & Leasing
  17. Retail Trade: Low
    Retail Trade
  18. Transportation & Warehousing: Low
    Transportation & Warehousing
  19. Utilities: Low
    Utilities
  20. Wholesale Trade: Low
    Wholesale Trade

Focus on What Matters

  1. See Everything.
  2. Identify True Risk.
  3. Proactively Mitigate Threats.

Let's talk!

background