CVE-2015-0128: XSS
Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix4, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0124.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0128?
CVE-2015-0128 is rated as a medium severity vulnerability due to its potential for exploitation via cross-site scripting (XSS).
How do I fix CVE-2015-0128?
To fix CVE-2015-0128, update IBM Rational Quality Manager to at least version 3.0.1.6, 4.0.7, or 5.0.2 which contains the appropriate patches.
Who can be affected by CVE-2015-0128?
CVE-2015-0128 affects remote authenticated users of IBM Rational Quality Manager versions 2.x to 5.x prior to the specified patched versions.
What impact does CVE-2015-0128 have on users?
The exploitation of CVE-2015-0128 allows attackers to inject arbitrary web scripts or HTML, potentially compromising user data and sessions.
What products are vulnerable to CVE-2015-0128?
Vulnerable products include IBM Rational Quality Manager versions 2.x, 3.x, 4.x, and 5.x before their respective fixes.