CVE-2016-3014: XSS
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Quality Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Team Concert 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational DOORS Next Generation 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3014?
CVE-2016-3014 is classified as a medium severity vulnerability.
How do I fix CVE-2016-3014?
To resolve CVE-2016-3014, update to IBM Rational Collaborative Lifecycle Management versions 4.0.7 iFix11 or 5.0.2 iFix17 and corresponding updates for other affected products.
What types of vulnerabilities does CVE-2016-3014 have potential impacts on?
CVE-2016-3014 can lead to cross-site scripting (XSS) attacks, allowing attackers to execute malicious scripts in the context of a user's session.
Which IBM products are affected by CVE-2016-3014?
CVE-2016-3014 affects IBM Rational Collaborative Lifecycle Management, Rational Quality Manager, Rational Team Concert, and several other IBM software products.
When was CVE-2016-3014 disclosed?
CVE-2016-3014 was published on March 15, 2016.