First published: Thu Aug 30 2018(Updated: )
Insufficient input validation in the gridExcelExport functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute reflected cross-site scripting attacks.
Credit: vuln@ca.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Project Portfolio Management | <=14.3 | |
Broadcom Project Portfolio Management | =14.4 | |
Broadcom Project Portfolio Management | =15.1 | |
Ca Project Portfolio Management | =15.2-cp5 | |
Ca Project Portfolio Management | =15.3-cp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13825 is considered a high severity vulnerability due to its potential for remote execution of reflected cross-site scripting attacks.
To fix CVE-2018-13825, upgrade to CA PPM versions later than 15.3 CP2 or apply security patches provided by Broadcom.
CVE-2018-13825 affects CA PPM versions 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below.
CVE-2018-13825 allows remote attackers to execute reflected cross-site scripting attacks due to insufficient input validation.
The affected software for CVE-2018-13825 is developed by Broadcom, under the brand CA Project Portfolio Management.