CVE-2015-0122: XSS
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0123.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0122?
CVE-2015-0122 has been classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2015-0122?
To mitigate CVE-2015-0122, it's recommended to update IBM Rational Team Concert to version 3.0.1.6 iFix 5 or higher.
What versions of IBM Rational Team Concert are affected by CVE-2015-0122?
CVE-2015-0122 affects IBM Rational Team Concert versions 2.x, 3.x before 3.0.1.6, 4.x before 4.0.7, and 5.x before 5.0.2.
Who can exploit CVE-2015-0122?
CVE-2015-0122 can be exploited by remote authenticated users who can craft arbitrary URLs.
What type of vulnerability is CVE-2015-0122?
CVE-2015-0122 is a cross-site scripting (XSS) vulnerability, which allows the injection of arbitrary web scripts or HTML.