CVE-2018-1983: XSS
Published Mar 8, 2019
·Updated
IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 154136.
Affected Software
2 affected components
IBM Rational Collaborative Lifecycle Management>=5.0<=6.0.6
IBM Rational Team Concert>=5.0<=6.0.6
Event History
Mar 14, 2019
CVE Published
10:29 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-1983.
2
What is the severity rating of CVE-2018-1983?
CVE-2018-1983 has a severity rating of 5.4 (medium).
3
What is the CWE ID associated with CVE-2018-1983?
CVE-2018-1983 is associated with CWE ID 79.
4
How does CVE-2018-1983 affect IBM Rational Team Concert?
CVE-2018-1983 allows users to embed arbitrary JavaScript code in the Web UI of IBM Rational Team Concert, potentially leading to credentials disclosure within a trusted session.
5
How can I fix CVE-2018-1983?
To fix CVE-2018-1983, apply the necessary security patches or updates provided by IBM.