CVE-2014-6144: XSS
Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6144?
CVE-2014-6144 has a medium severity level as it allows authenticated users to inject arbitrary web scripts or HTML.
How do I fix CVE-2014-6144?
To fix CVE-2014-6144, update your IBM Rational Quality Manager to version 3.0.1.6 iFix 5 or later, 4.0.7 iFix 3 or later, or 5.0.2 or later.
What versions of IBM Rational Quality Manager are affected by CVE-2014-6144?
CVE-2014-6144 affects IBM Rational Quality Manager versions 2.x, 3.x before 3.0.1.6, 4.x before 4.0.7, and 5.x before 5.0.2.
Can attackers exploit CVE-2014-6144 remotely?
Yes, attackers can exploit CVE-2014-6144 remotely by using a crafted URL that takes advantage of the XSS vulnerability.
What type of vulnerability is CVE-2014-6144?
CVE-2014-6144 is classified as a Cross-site Scripting (XSS) vulnerability.