First published: Tue Oct 02 2018(Updated: )
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138440.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational Quality Manager | >=5.0<=5.0.2 | |
IBM Rational Quality Manager | >=6.0<=6.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1404 is classified as a medium risk due to its potential for exploiting cross-site scripting vulnerabilities.
To fix CVE-2018-1404, upgrade IBM Rational Quality Manager to version 6.0.6 or above, or to any version higher than 5.0.2.
IBM Rational Quality Manager versions 5.0 through 5.02 and 6.0 through 6.0.6 are affected by CVE-2018-1404.
CVE-2018-1404 allows attackers to embed arbitrary JavaScript code into the Web UI, potentially leading to credentials disclosure.
Yes, user interaction is typically required to exploit CVE-2018-1404 as it involves crossing user interfaces.