CVE-2018-6587: XSS
Published Mar 29, 2018
·Updated
CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.
Affected Software
7 affected components
CA API Developer Portal=3.5
CA API Developer Portal=3.5-cr1
CA API Developer Portal=3.5-cr2
CA API Developer Portal=3.5-cr3
CA API Developer Portal=3.5-cr4
CA API Developer Portal=3.5-cr5
CA API Developer Portal=3.5-cr6
Remediation
Event History
Mar 29, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Data Sourced
via NVD·01:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6587?
CVE-2018-6587 has been classified with a medium severity due to its potential impact on user data security.
2
How do I fix CVE-2018-6587?
Fix CVE-2018-6587 by applying the latest patch or update provided for CA API Developer Portal version 3.5.
3
What is the nature of the vulnerability in CVE-2018-6587?
CVE-2018-6587 is a reflected cross-site scripting vulnerability related to the widgetID variable.
4
Which versions of CA API Developer Portal are affected by CVE-2018-6587?
CVE-2018-6587 affects CA API Developer Portal versions 3.5 up to and including 3.5 CR6.
5
Can CVE-2018-6587 be exploited remotely?
Yes, CVE-2018-6587 can be exploited remotely by injecting malicious scripts into the widgetID variable.