CVE-2018-1408Cross-site Scripting in IBM Rational Team Concert

Severity
5.4MEDIUMNVD
EPSS
0.2%
top 60.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 10
Latest updateMay 13

Description

IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138446.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

NVDibm/rational_team_concert5.05.0.2+1
CVEListV5ibm/rational_team_concert9 versions+8

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5g3v-wcj6-q7xp: IBM Rational Team Concert 52022-05-13
CVEList
CVE-2018-1408: IBM Rational Team Concert 52018-07-10

💥Exploits & PoCs

3
Exploit-DB
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass2018-12-04
Exploit-DB
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Cross-Site Scripting2018-12-03
Exploit-DB
LibreOffice < 6.0.1 - '=WEBSERVICE' Remote Arbitrary File Disclosure2018-02-10

💬Community

1
Bugzilla
CVE-2018-20467 ImageMagick: infinite loop in coders/bmp.c2019-01-09
CVE-2018-1408 — Cross-site Scripting in IBM | cvebase