CVE-2015-0123: XSS
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0122.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0123?
CVE-2015-0123 has a medium severity rating, as it allows authenticated users to exploit the application through cross-site scripting.
How do I fix CVE-2015-0123?
To fix CVE-2015-0123, upgrade to IBM Rational Team Concert version 3.0.1.6 iFix 5, 4.0.7 iFix 3, or 5.0.2 or later.
Who is affected by CVE-2015-0123?
CVE-2015-0123 affects users of IBM Rational Team Concert versions 2.x, 3.x, 4.x, and 5.x prior to the specified updates.
What types of attacks can CVE-2015-0123 facilitate?
CVE-2015-0123 can enable attackers to perform cross-site scripting attacks, potentially leading to session hijacking or redirection.
How can I determine if my system is vulnerable to CVE-2015-0123?
To determine if your system is vulnerable to CVE-2015-0123, check the version of IBM Rational Team Concert installed against the patched versions.