CVE-2016-0331: XSS
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 6.0.1 and 6.0.2 before 6.0.2 iFix2 and Rational Collaborative Lifecycle Management 6.0.1 and 6.0.2 before 6.0.2 iFix2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0331?
CVE-2016-0331 is classified as a cross-site scripting (XSS) vulnerability which can lead to significant security risks.
How do I fix CVE-2016-0331?
To fix CVE-2016-0331, update to IBM Rational Team Concert and Rational Collaborative Lifecycle Management version 6.0.2 iFix2 or later.
Who is affected by CVE-2016-0331?
CVE-2016-0331 affects users of IBM Rational Team Concert and IBM Rational Collaborative Lifecycle Management versions 6.0.1 and 6.0.2 before the respective iFix2 release.
What is the impact of exploiting CVE-2016-0331?
Exploiting CVE-2016-0331 allows authenticated users to inject arbitrary web script or HTML into web applications.
Is CVE-2016-0331 easy to exploit?
CVE-2016-0331 may be relatively easy to exploit for remote authenticated users with malicious intent.