CVE-2018-1826: XSS
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150429.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-1826?
CVE-2018-1826 is a vulnerability in IBM Rational Collaborative Lifecycle Management that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
Which IBM software products are affected by CVE-2018-1826?
IBM Rational Collaborative Lifecycle Management, IBM Rational DOORS Next Generation, IBM Rational Engineering Lifecycle Manager, IBM Rational Quality Manager, IBM Rational Rhapsody Design Manager, IBM Rational Software Architect Design Manager, IBM Rational Team Concert, and IBM Rhapsody Model Manager are affected by CVE-2018-1826.
What is the severity of CVE-2018-1826?
The severity of CVE-2018-1826 is medium with a severity value of 5.4.
How can CVE-2018-1826 be exploited?
CVE-2018-1826 can be exploited by embedding arbitrary JavaScript code in the Web UI of affected IBM software products.
Are there any references for CVE-2018-1826?
Yes, you can find references for CVE-2018-1826 on the IBM support website and the IBM X-Force Exchange.