CVE-2018-6587
Description
CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A reflected XSS vulnerability exists in the widgetID variable of CA API Developer Portal 3.5 up to CR6, allowing remote attackers to execute arbitrary script in the user's browser session.
Vulnerability
A reflected cross-site scripting (XSS) vulnerability exists in CA API Developer Portal versions 3.5 GA through 3.5 CR6. The flaw is located in handling of the widgetID variable [1]. An attacker can inject arbitrary script code via a crafted request, which is then reflected back to the user without proper sanitization.
Exploitation
The attacker does not require authentication and can deliver the malicious payload via a crafted URL. If the victim visits the crafted link while being authenticated to the portal, the injected script executes in the context of the user's session. No user interaction beyond clicking the link is required [1].
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser within the security context of the affected portal. This can lead to session hijacking, defacement, or redirection to malicious sites. The risk rating assigned to this vulnerability is Medium [1].
Mitigation
The vendor (CA Technologies, now Broadcom) released CA API Developer Portal 3.5 CR7, which addresses this vulnerability. Customers are advised to upgrade to version 3.5 CR7 or later. Portal version 4 and newer are not affected [1]. No workaround was provided in the available references.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=3.5 CR6
- CA Technologies/CA API Developer Portalv5Range: 3.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securitytracker.com/id/1040603mitrevdb-entryx_refsource_SECTRACK
- support.ca.com/us/product-content/recommended-reading/security-notices/ca20180328-01--security-notice-for-ca-api-developer-portal.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.