CVE-2015-0124: XSS
Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix4, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0128.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0124?
CVE-2015-0124 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2015-0124?
To fix CVE-2015-0124, upgrade IBM Rational Quality Manager to version 3.0.1.6 iFix4, 4.0.7 iFix3, or 5.0.2 or later.
Who is affected by CVE-2015-0124?
CVE-2015-0124 affects users of IBM Rational Quality Manager versions 2.x, 3.x, 4.x, and 5.x prior to specific iFixes.
What types of attacks can be executed due to CVE-2015-0124?
CVE-2015-0124 allows remote authenticated users to execute arbitrary web scripts or HTML via crafted URLs.
Is CVE-2015-0124 a known issue in IBM software?
Yes, CVE-2015-0124 is a known cross-site scripting issue reported in multiple versions of IBM Rational Quality Manager.