CVE-2018-1558: XSS
IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142956.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-1558?
CVE-2018-1558 is a vulnerability in IBM Rational Collaborative Lifecycle Management that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
Which software versions are affected by CVE-2018-1558?
IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6 are affected by CVE-2018-1558.
How severe is CVE-2018-1558?
CVE-2018-1558 has a severity score of 5.4, indicating a medium-level vulnerability.
How can I fix CVE-2018-1558?
To fix CVE-2018-1558, users should update their IBM Rational Collaborative Lifecycle Management software to version 6.0.7 or later.
Where can I find more information about CVE-2018-1558?
You can find more information about CVE-2018-1558 on the Debian security tracker, the IBM support website, and the IBM X-Force Exchange.