CVE-2015-7474: XSS
Cross-site scripting (XSS) vulnerability in Jazz Foundation in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108501.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7474?
CVE-2015-7474 is categorized as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2015-7474?
To fix CVE-2015-7474, update IBM Rational Engineering Lifecycle Manager to version 3.0.1.6 iFix7 Interim Fix 1, 4.0.7 iFix10, 5.0.2 iFix15, or 6.0.1 iFix4, or later.
Who is affected by CVE-2015-7474?
CVE-2015-7474 affects users of IBM Rational Engineering Lifecycle Manager versions prior to the specified fixed versions.
What causes CVE-2015-7474?
CVE-2015-7474 is caused by insufficient validation of user input, allowing attackers to inject arbitrary web scripts or HTML.
Is there a workaround for CVE-2015-7474?
There is no documented workaround for CVE-2015-7474; upgrading to the latest version is the recommended approach.