CVE-2018-13825: XSS
Insufficient input validation in the gridExcelExport functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute reflected cross-site scripting attacks.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13825?
CVE-2018-13825 is considered a high severity vulnerability due to its potential for remote execution of reflected cross-site scripting attacks.
How do I fix CVE-2018-13825?
To fix CVE-2018-13825, upgrade to CA PPM versions later than 15.3 CP2 or apply security patches provided by Broadcom.
Which software is affected by CVE-2018-13825?
CVE-2018-13825 affects CA PPM versions 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below.
What type of attack does CVE-2018-13825 allow?
CVE-2018-13825 allows remote attackers to execute reflected cross-site scripting attacks due to insufficient input validation.
Who is the vendor for the affected software in CVE-2018-13825?
The affected software for CVE-2018-13825 is developed by Broadcom, under the brand CA Project Portfolio Management.