CVE-2018-1690: XSS
IBM Rhapsody Model Manager 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145510.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1690?
The severity of CVE-2018-1690 is medium with a CVSS score of 5.4.
What is the impact of CVE-2018-1690?
CVE-2018-1690 allows users to embed arbitrary JavaScript code in the IBM Rhapsody Model Manager Web UI, potentially leading to credentials disclosure within a trusted session.
How can I verify if my IBM Rhapsody Model Manager version 6.0.6 is affected by CVE-2018-1690?
You can verify if your IBM Rhapsody Model Manager version 6.0.6 is affected by CVE-2018-1690 by checking the official IBM Rhapsody Model Manager 6.0.6 documentation or contacting IBM support.
Is there a fix available for CVE-2018-1690?
Yes, a fix for CVE-2018-1690 is available. Please refer to the official IBM Rhapsody Model Manager 6.0.6 documentation or contact IBM support for more information on how to obtain and apply the fix.
Are there any known exploits for CVE-2018-1690?
There are currently no known exploits for CVE-2018-1690. However, it is highly recommended to apply the fix provided by IBM to protect against potential attacks.