First published: Tue Aug 07 2018(Updated: )
IBM Rhapsody Model Manager 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145510.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rhapsody Model Manager | =6.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1690 is medium with a CVSS score of 5.4.
CVE-2018-1690 allows users to embed arbitrary JavaScript code in the IBM Rhapsody Model Manager Web UI, potentially leading to credentials disclosure within a trusted session.
You can verify if your IBM Rhapsody Model Manager version 6.0.6 is affected by CVE-2018-1690 by checking the official IBM Rhapsody Model Manager 6.0.6 documentation or contacting IBM support.
Yes, a fix for CVE-2018-1690 is available. Please refer to the official IBM Rhapsody Model Manager 6.0.6 documentation or contact IBM support for more information on how to obtain and apply the fix.
There are currently no known exploits for CVE-2018-1690. However, it is highly recommended to apply the fix provided by IBM to protect against potential attacks.