CVE-2018-1535

MEDIUM

IBM Rational Rhapsody and Software Architect Design Manager 5.0-5.0.2, 6.0-6.0.5 - Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Description

IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124557.

References (2)

Core 2
Core References
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/142557
Patch, Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=ibm10716029

Scores

CVSS v3 5.4
EPSS 0.0067
EPSS Percentile 48.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
ibm/rational_rhapsody_design_manager 5.0 - 5.0.2
ibm/rational_software_architect_design_manager 5.0 - 5.0.2
Published Jul 19, 2018
Tracked Since Feb 18, 2026