First published: Tue Jun 25 2019(Updated: )
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150429.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational Collaborative Lifecycle Management | >=6.0<=6.0.6.1 | |
IBM Rational DOORS Next Generation | >=6.0<=6.0.6.1 | |
IBM Rational Engineering Lifecycle Manager | >=6.0<=6.0.6.1 | |
IBM Rational Quality Manager | >=6.0<=6.0.6.1 | |
IBM Rational Rhapsody Design Manager | >=6.0<=6.0.6.1 | |
IBM Rational Software Architect Design Manager | >=6.0<=6.0.1 | |
IBM Rational Team Concert | >=6.0<=6.0.6.1 | |
IBM Rhapsody Model Manager | >=6.0.5<=6.0.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1826 is a vulnerability in IBM Rational Collaborative Lifecycle Management that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
IBM Rational Collaborative Lifecycle Management, IBM Rational DOORS Next Generation, IBM Rational Engineering Lifecycle Manager, IBM Rational Quality Manager, IBM Rational Rhapsody Design Manager, IBM Rational Software Architect Design Manager, IBM Rational Team Concert, and IBM Rhapsody Model Manager are affected by CVE-2018-1826.
The severity of CVE-2018-1826 is medium with a severity value of 5.4.
CVE-2018-1826 can be exploited by embedding arbitrary JavaScript code in the Web UI of affected IBM software products.
Yes, you can find references for CVE-2018-1826 on the IBM support website and the IBM X-Force Exchange.