Cross-Site Scripting in IBM Rational Design Manager and Software Architect
CVE-2018-1535
5.4MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 19 July 2018
What is CVE-2018-1535?
IBM Rational Rhapsody Design Manager and Rational Software Architect are susceptible to a cross-site scripting vulnerability. This flaw permits attackers to inject arbitrary JavaScript code through the Web UI, potentially compromising user sessions and resulting in unauthorized access to sensitive information. It is crucial for users of these IBM products to apply the latest updates and patches to mitigate the risk of exploitation.
Affected Version(s)
Rational Rhapsody Design Manager 5.0
Rational Rhapsody Design Manager 5.0.2
Rational Rhapsody Design Manager 5.0.1