CVE-2015-7485: XSS
Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108626.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7485?
CVE-2015-7485 is classified as a high severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2015-7485?
To fix CVE-2015-7485, upgrade IBM Rational Engineering Lifecycle Manager to versions 3.0.1.6 iFix7 Interim Fix 1, 4.0.7 iFix10, 5.0.2 iFix15, or 6.0.1 iFix4 or later.
What types of attacks can exploit CVE-2015-7485?
CVE-2015-7485 can be exploited by attackers to inject arbitrary web scripts or HTML into affected installations.
Which versions of IBM Rational Engineering Lifecycle Manager are affected by CVE-2015-7485?
Affected versions include 3.0 before 3.0.1.6, 4.0 before 4.0.7, 5.0 before 5.0.2, and 6.0 before 6.0.1.
Who is at risk from CVE-2015-7485?
Organizations using vulnerable versions of IBM Rational Engineering Lifecycle Manager are at risk from CVE-2015-7485.