CVE-2013-5404: XSS
Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other products, allows remote authenticated users to inject arbitrary web script or HTML via vectors involving an IFRAME element.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5404?
CVE-2013-5404 is classified as a moderate severity vulnerability affecting multiple versions of IBM Rational Quality Manager, Rational Requirements Composer, and Rational Team Concert.
How do I fix CVE-2013-5404?
To address CVE-2013-5404, upgrade to the latest patched versions of IBM Rational Quality Manager, Rational Requirements Composer, or Rational Team Concert as recommended by IBM.
Who is affected by CVE-2013-5404?
Remote authenticated users of IBM Rational Quality Manager versions 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5 are affected by CVE-2013-5404.
What type of vulnerability is CVE-2013-5404?
CVE-2013-5404 is a Cross-Site Scripting (XSS) vulnerability.
What impacts can CVE-2013-5404 have?
CVE-2013-5404 can allow remote authenticated users to execute arbitrary scripts in the context of a vulnerable web application.