CVE-2018-1585

IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143498.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:rational_rhapsody_design_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_rhapsody_design_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_software_architect_design_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_software_architect_design_manager:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-07-19 14:29

Updated : 2024-02-04 20:03


NVD link : CVE-2018-1585

Mitre link : CVE-2018-1585

CVE.ORG link : CVE-2018-1585


JSON object : View

Products Affected

ibm

  • rational_software_architect_design_manager
  • rational_rhapsody_design_manager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')