CVE-2018-1951: XSS
IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153494.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for the IBM Publishing Engine vulnerability?
The vulnerability ID for the IBM Publishing Engine vulnerability is CVE-2018-1951.
What is the severity level of CVE-2018-1951?
The severity level of CVE-2018-1951 is medium (5.4).
Which software versions are affected by CVE-2018-1951?
IBM Publishing Engine versions 2.1.2, 6.0.5, and 6.0.6 are affected by CVE-2018-1951.
What is cross-site scripting (XSS)?
Cross-site scripting (XSS) is a type of security vulnerability where attackers inject malicious scripts into web pages viewed by other users.
How can the IBM Publishing Engine vulnerability be fixed?
To fix the IBM Publishing Engine vulnerability, apply the patches or updates provided by IBM.