CVE-2016-0285: XSS
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0285?
CVE-2016-0285 has a moderate severity level due to its cross-site scripting nature.
How do I fix CVE-2016-0285?
To fix CVE-2016-0285, upgrade IBM Rational Collaborative Lifecycle Management to the specified versions that include the security patch.
What products are affected by CVE-2016-0285?
CVE-2016-0285 affects multiple versions of IBM Rational Collaborative Lifecycle Management and Rational Quality Manager prior to the specified iFix levels.
What type of vulnerability is CVE-2016-0285?
CVE-2016-0285 is a cross-site scripting (XSS) vulnerability.
Where can I find more information about CVE-2016-0285?
Information about CVE-2016-0285 can be found in the official IBM support documentation.