First published: Fri Aug 17 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the file-upload functionality in the Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 allows remote authenticated users to inject arbitrary web script or HTML via the File Description field.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational ClearQuest | =7.1.1.1 | |
IBM Rational ClearQuest | =7.1.1.2 | |
IBM Rational ClearQuest | =7.1.1.3 | |
IBM Rational ClearQuest | =7.1.1.4 | |
IBM Rational ClearQuest | =7.1.1.5 | |
IBM Rational ClearQuest | =7.1.1.6 | |
IBM Rational ClearQuest | =7.1.1.7 | |
IBM Rational ClearQuest | =7.1.1.8 | |
IBM Rational ClearQuest | =7.1.2 | |
IBM Rational ClearQuest | =7.1.2.1 | |
IBM Rational ClearQuest | =7.1.2.2 | |
IBM Rational ClearQuest | =7.1.2.3 | |
IBM Rational ClearQuest | =7.1.2.4 | |
IBM Rational ClearQuest | =7.1.2.5 | |
IBM Rational ClearQuest | =7.1.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2169 has a medium severity level due to its potential for allowing XSS attacks.
To fix CVE-2012-2169, upgrade IBM Rational ClearQuest to version 7.1.2.7 or later.
CVE-2012-2169 affects users of IBM Rational ClearQuest versions prior to 7.1.2.7.
CVE-2012-2169 is classified as a Cross-site scripting (XSS) vulnerability.
No, CVE-2012-2169 requires remote authenticated users to exploit the vulnerability.