CVE-2018-6586: XSS
Published Mar 29, 2018
·Updated
CA API Developer Portal 3.5 up to and including 3.5 CR6 has a stored cross-site scripting vulnerability related to profile picture processing.
Affected Software
7 affected components
CA API Developer Portal=3.5
CA API Developer Portal=3.5-cr1
CA API Developer Portal=3.5-cr2
CA API Developer Portal=3.5-cr3
CA API Developer Portal=3.5-cr4
CA API Developer Portal=3.5-cr5
CA API Developer Portal=3.5-cr6
Remediation
Event History
Mar 29, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Data Sourced
via NVD·01:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6586?
The severity of CVE-2018-6586 is classified as medium, due to the potential for stored cross-site scripting attacks.
2
How do I fix CVE-2018-6586?
To fix CVE-2018-6586, you should upgrade to a patched version of CA API Developer Portal that addresses this vulnerability.
3
What is the impact of CVE-2018-6586?
The impact of CVE-2018-6586 could allow an attacker to execute arbitrary JavaScript in the context of users' profiles.
4
Which versions are affected by CVE-2018-6586?
CVE-2018-6586 affects CA API Developer Portal versions 3.5 up to and including 3.5 CR6.
5
Is CVE-2018-6586 a common vulnerability?
CVE-2018-6586 is a specific case of stored cross-site scripting, which is a common web application vulnerability.