CVE-2018-6590
Description
CA API Developer Portal 4.x, prior to v4.2.5.3 and v4.2.7.1, has an unspecified reflected cross-site scripting vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CA API Developer Portal 4.x before 4.2.5.3 and 4.2.7.1 contains a reflected cross-site scripting vulnerability due to insufficient parameter filtering.
Vulnerability
CA API Developer Portal versions 4.0, 4.1, and 4.2.x prior to 4.2.5.3 and 4.2.7.1 contain a reflected cross-site scripting (XSS) vulnerability [1]. The issue exists within the web user interface and is caused by insufficient parameter filtering, allowing an attacker to inject arbitrary script [1].
Exploitation
A remote attacker can exploit this vulnerability by crafting a malicious URL or request containing a script payload in an unsanitized parameter [1]. The attacker must trick a user into clicking or accessing the crafted link, which causes the injected script to execute within the victim's browser context [1]. No authentication is required for the attacker to deliver the payload, though user interaction (clicking a link) is necessary [1].
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session [1]. This can lead to unauthorized actions such as session hijacking, credential theft, or defacement of the portal interface. The impact is rated as Medium severity by CA [1].
Mitigation
CA has released updates to address the vulnerability. Customers on affected versions (v4.0, v4.1, v4.2.x) should upgrade to CA API Developer Portal v4.2.5.3 or v4.2.7.1 (or later) [1]. No workarounds are provided in the advisory [1]. Version 3.5 is listed as unaffected [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: >=4.0, <4.2.5.3, <4.2.7.1
- ca technologies/CA API Developer Portalv5Range: 4.x
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securitytracker.com/id/1041416mitrevdb-entryx_refsource_SECTRACK
- support.ca.com/us/product-content/recommended-reading/security-notices/ca20180802-01--security-notice-for-ca-api-developer-portal.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.