First published: Fri Jan 04 2019(Updated: )
IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153494.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational Publishing Engine | =2.1.2 | |
IBM Rational Publishing Engine | =6.0.5 | |
IBM Rational Publishing Engine | =6.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the IBM Publishing Engine vulnerability is CVE-2018-1951.
The severity level of CVE-2018-1951 is medium (5.4).
IBM Publishing Engine versions 2.1.2, 6.0.5, and 6.0.6 are affected by CVE-2018-1951.
Cross-site scripting (XSS) is a type of security vulnerability where attackers inject malicious scripts into web pages viewed by other users.
To fix the IBM Publishing Engine vulnerability, apply the patches or updates provided by IBM.