CVE-2018-6588: XSS
Published Mar 29, 2018
·Updated
CA API Developer Portal 3.5 up to and including 3.5 CR5 has a reflected cross-site scripting vulnerability related to the apiExplorer.
Affected Software
6 affected components
CA API Developer Portal=3.5
CA API Developer Portal=3.5-cr1
CA API Developer Portal=3.5-cr2
CA API Developer Portal=3.5-cr3
CA API Developer Portal=3.5-cr4
CA API Developer Portal=3.5-cr5
Remediation
Event History
Mar 29, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Data Sourced
via NVD·01:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6588?
CVE-2018-6588 has been identified as having a critical severity level due to its potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2018-6588?
To remediate CVE-2018-6588, upgrade CA API Developer Portal to version 3.5 CR6 or later.
3
What software versions are affected by CVE-2018-6588?
CA API Developer Portal versions 3.5 through 3.5 CR5 are impacted by CVE-2018-6588.
4
What type of vulnerability is CVE-2018-6588?
CVE-2018-6588 is a reflected cross-site scripting vulnerability in the CA API Developer Portal.
5
What are the potential impacts of CVE-2018-6588?
Exploiting CVE-2018-6588 may allow attackers to execute arbitrary scripts in the context of the user's browser.