Medium severity6.1NVD Advisory· Published Mar 29, 2018· Updated Jun 17, 2026
CVE-2018-6587
CVE-2018-6587
Description
CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:a:ca:api_developer_portal:3.5:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:ca:api_developer_portal:3.5:*:*:*:*:*:*:*
- cpe:2.3:a:ca:api_developer_portal:3.5:cr1:*:*:*:*:*:*
- cpe:2.3:a:ca:api_developer_portal:3.5:cr2:*:*:*:*:*:*
- cpe:2.3:a:ca:api_developer_portal:3.5:cr3:*:*:*:*:*:*
- cpe:2.3:a:ca:api_developer_portal:3.5:cr4:*:*:*:*:*:*
- cpe:2.3:a:ca:api_developer_portal:3.5:cr5:*:*:*:*:*:*
- cpe:2.3:a:ca:api_developer_portal:3.5:cr6:*:*:*:*:*:*
- Range: <=3.5 CR6
- CA Technologies/CA API Developer Portalv5Range: 3.5
Patches
Vulnerability mechanics
References
2- support.ca.com/us/product-content/recommended-reading/security-notices/ca20180328-01--security-notice-for-ca-api-developer-portal.htmlnvdPatchVendor Advisory
- www.securitytracker.com/id/1040603nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.