CVE-2016-6035: XSS
IBM Rational Quality Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 116896.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6035?
CVE-2016-6035 is considered a high severity vulnerability due to its potential for credential disclosure through cross-site scripting.
How do I fix CVE-2016-6035?
To fix CVE-2016-6035, users must update their IBM Rational Quality Manager or IBM Rational Team Concert to the latest patched version provided by IBM.
Which versions of software are affected by CVE-2016-6035?
CVE-2016-6035 affects multiple versions of IBM Rational Quality Manager and IBM Rational Team Concert from 4.0.0 to 6.0.2.
What types of attacks can exploit CVE-2016-6035?
CVE-2016-6035 can be exploited through cross-site scripting attacks allowing attackers to inject JavaScript into the web interface.
Is user input filtering a solution for CVE-2016-6035?
While user input filtering can mitigate risks, it is essential to apply the official fixes to fully address CVE-2016-6035.