CVE-2018-1758: XSS
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148605.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-1758.
What is the severity of CVE-2018-1758?
The severity of CVE-2018-1758 is medium (5.4).
Which software versions are affected by CVE-2018-1758?
IBM Rational Collaborative Lifecycle Management versions 6.0 through 6.0.6.1
How does CVE-2018-1758 impact the affected software?
CVE-2018-1758 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
Is there a fix available for CVE-2018-1758?
Yes, IBM has released fixes for the affected software versions. It is recommended to update to the latest version.