CVE-2016-6022: XSS
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000784.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6022?
CVE-2016-6022 has a medium severity rating as it allows cross-site scripting, potentially leading to credentials disclosure.
How do I fix CVE-2016-6022?
To fix CVE-2016-6022, ensure that you apply the latest security patches provided by IBM for Rational Quality Manager.
What versions of IBM Rational Quality Manager are affected by CVE-2016-6022?
CVE-2016-6022 affects IBM Rational Quality Manager versions 4.0 through 6.0.3.
Can CVE-2016-6022 lead to data breaches?
Yes, CVE-2016-6022 can lead to data breaches as it allows attackers to execute arbitrary JavaScript code in the user's session.
Is CVE-2016-6022 exploit available in the wild?
There is no public information indicating that exploits for CVE-2016-6022 are actively being used in the wild.