CVE-2016-6030: XSS
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6030?
CVE-2016-6030 is classified as a medium severity vulnerability.
How do I fix CVE-2016-6030?
To fix CVE-2016-6030, you should apply the latest security updates provided by IBM for the affected versions of Rational Collaborative Lifecycle Management.
Which versions of IBM Collaborative Lifecycle Management are affected by CVE-2016-6030?
CVE-2016-6030 affects IBM Collaborative Lifecycle Management versions 4.0.0 to 6.0.2.
What type of attack does CVE-2016-6030 allow?
CVE-2016-6030 allows cross-site scripting (XSS) attacks, enabling attackers to inject arbitrary JavaScript.
What are the potential consequences of exploiting CVE-2016-6030?
Exploiting CVE-2016-6030 could lead to the disclosure of user credentials in a trusted session.