CVE-2018-1535
MEDIUMIBM Rational Rhapsody and Software Architect Design Manager 5.0-5.0.2, 6.0-6.0.5 - Stored Cross-Site Scripting
Title source: llmDescription
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124557.
References (2)
Core 2
Core References
VDB Entry, Vendor Advisory vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/142557
Patch, Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=ibm10716029
Scores
CVSS v3
5.4
EPSS
0.0067
EPSS Percentile
48.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
ibm/rational_rhapsody_design_manager
5.0 - 5.0.2
ibm/rational_software_architect_design_manager
5.0 - 5.0.2
Published
Jul 19, 2018
Tracked Since
Feb 18, 2026