CVE-2014-0846: XSS
Cross-site scripting (XSS) vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Rational Requirements Composerto a version that resolves this vulnerability.Fixed in 3.0.1.6 iFix2 - Upgrade
Upgrade
IBM Rational Requirements Composerto a version that resolves this vulnerability.Fixed in 4.0.6 - Upgrade
Upgrade
IBM Rational DOORS Next Generationto a version that resolves this vulnerability.Fixed in 4.0.6
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0846?
The severity of CVE-2014-0846 is considered high due to its potential for allowing remote authenticated users to execute malicious scripts.
How do I fix CVE-2014-0846?
To fix CVE-2014-0846, users should update IBM Rational Requirements Composer and Rational DOORS Next Generation to the latest fixed versions.
Who is affected by CVE-2014-0846?
CVE-2014-0846 affects users of IBM Rational Requirements Composer versions before 3.0.1.6 iFix2 and IBM Rational DOORS Next Generation before 4.0.6.
What type of vulnerability is CVE-2014-0846?
CVE-2014-0846 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web script or HTML.
Can CVE-2014-0846 be exploited remotely?
Yes, CVE-2014-0846 can be exploited remotely by authenticated users through crafted URLs.