First published: Thu Mar 29 2018(Updated: )
CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.
Credit: vuln@ca.com
Affected Software | Affected Version | How to fix |
---|---|---|
CA API Developer Portal | =3.5 | |
CA API Developer Portal | =3.5-cr1 | |
CA API Developer Portal | =3.5-cr2 | |
CA API Developer Portal | =3.5-cr3 | |
CA API Developer Portal | =3.5-cr4 | |
CA API Developer Portal | =3.5-cr5 | |
CA API Developer Portal | =3.5-cr6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6587 has been classified with a medium severity due to its potential impact on user data security.
Fix CVE-2018-6587 by applying the latest patch or update provided for CA API Developer Portal version 3.5.
CVE-2018-6587 is a reflected cross-site scripting vulnerability related to the widgetID variable.
CVE-2018-6587 affects CA API Developer Portal versions 3.5 up to and including 3.5 CR6.
Yes, CVE-2018-6587 can be exploited remotely by injecting malicious scripts into the widgetID variable.