First published: Fri Mar 13 2015(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager (RQM) 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational Quality Manager | =4.0 | |
IBM Rational Quality Manager | =4.0.0.1 | |
IBM Rational Quality Manager | =4.0.0.2 | |
IBM Rational Quality Manager | =4.0.1 | |
IBM Rational Quality Manager | =4.0.2 | |
IBM Rational Quality Manager | =4.0.3 | |
IBM Rational Quality Manager | =4.0.4 | |
IBM Rational Quality Manager | =4.0.5 | |
IBM Rational Quality Manager | =4.0.7 | |
IBM Rational Quality Manager | =5.0.0 | |
IBM Rational Quality Manager | =5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0129 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2015-0129, upgrade IBM Rational Quality Manager to version 4.0.7 iFix3 or 5.0.2 or later.
CVE-2015-0129 affects users of IBM Rational Quality Manager versions 4.0.x before 4.0.7 iFix3 and 5.x before 5.0.2.
CVE-2015-0129 allows remote authenticated users to inject arbitrary web script or HTML into the application.
CVE-2015-0129 is a client-side vulnerability that exploits how the application handles user input.