CVE-2016-2986: XSS
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 6.x before 6.0.1 iFix6, Rational Quality Manager 6.x before 6.0.1 iFix6, Rational Team Concert 6.x before 6.0.1 iFix6, Rational DOORS Next Generation 6.x before 6.0.1 iFix6, Rational Engineering Lifecycle Manager 6.x before 6.0.1 iFix6, and Rational Rhapsody Design Manager 6.x before 6.0.1 iFix6 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2986?
CVE-2016-2986 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2016-2986?
To fix CVE-2016-2986, upgrade to the latest IBM Engineering Lifecycle Manager, Rational Team Concert, Rational Quality Manager, or Rational DOORS Next Generation version at least 6.0.1 iFix6.
What products are affected by CVE-2016-2986?
CVE-2016-2986 affects multiple IBM products including Rational Collaborative Lifecycle Management, Rational Quality Manager, Rational Team Concert, and Rational DOORS Next Generation.
What type of vulnerability is CVE-2016-2986?
CVE-2016-2986 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages viewed by users.
Is there a known exploit for CVE-2016-2986?
As of now, there are no widely reported exploits specifically targeting CVE-2016-2986.