CVE-2014-4801: XSS
Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x through 2.0.1.1, 3.x before 3.0.1.6 iFix 4, 4.x before 4.0.7 iFix 2, and 5.x before 5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4801?
CVE-2014-4801 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2014-4801?
To fix CVE-2014-4801, upgrade IBM Rational Quality Manager to the latest version that has addressed this vulnerability.
Which versions are affected by CVE-2014-4801?
CVE-2014-4801 affects IBM Rational Quality Manager versions 2.x through 2.0.1.1, 3.x before 3.0.1.6, and 4.x before 4.0.7.
Can CVE-2014-4801 be exploited by remote users?
Yes, CVE-2014-4801 can be exploited by remote authenticated users through crafted URLs.
What type of attack is associated with CVE-2014-4801?
CVE-2014-4801 is associated with cross-site scripting (XSS) attacks.