First published: Thu Mar 29 2018(Updated: )
CA API Developer Portal 3.5 up to and including 3.5 CR5 has a reflected cross-site scripting vulnerability related to the apiExplorer.
Credit: vuln@ca.com
Affected Software | Affected Version | How to fix |
---|---|---|
CA API Developer Portal | =3.5 | |
CA API Developer Portal | =3.5-cr1 | |
CA API Developer Portal | =3.5-cr2 | |
CA API Developer Portal | =3.5-cr3 | |
CA API Developer Portal | =3.5-cr4 | |
CA API Developer Portal | =3.5-cr5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6588 has been identified as having a critical severity level due to its potential for reflected cross-site scripting attacks.
To remediate CVE-2018-6588, upgrade CA API Developer Portal to version 3.5 CR6 or later.
CA API Developer Portal versions 3.5 through 3.5 CR5 are impacted by CVE-2018-6588.
CVE-2018-6588 is a reflected cross-site scripting vulnerability in the CA API Developer Portal.
Exploiting CVE-2018-6588 may allow attackers to execute arbitrary scripts in the context of the user's browser.