CVE-2018-1536: XSS
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142558.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-1536.
Which products are affected by this vulnerability?
IBM Rational Rhapsody Design Manager versions 5.0 through 5.0.2 and 6.0 through 6.0.5, and IBM Rational Software Architect Design Manager versions 5.0 through 5.0.2 and 6.0 through 6.0.1 are affected.
What is the severity rating of CVE-2018-1536?
CVE-2018-1536 has a severity rating of 5.4 (medium).
What is the CWE category of this vulnerability?
The CWE category of this vulnerability is CWE-79.
How can I fix the cross-site scripting vulnerability in IBM Rational Rhapsody Design Manager and Rational Software Architect Design Manager?
To fix the cross-site scripting vulnerability, update IBM Rational Rhapsody Design Manager to version 5.0.3 or later, Rational Software Architect Design Manager to version 6.0.2 or later, or apply the recommended patches provided by IBM.