CVE-2016-6061: XSS
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6061?
CVE-2016-6061 is considered a medium severity vulnerability due to its potential for cross-site scripting and credential disclosure.
How do I fix CVE-2016-6061?
To resolve CVE-2016-6061, users should update to the latest version of IBM Rational Collaborative Lifecycle Management that has the vulnerability patched.
What types of systems are affected by CVE-2016-6061?
CVE-2016-6061 affects multiple versions of IBM Rational Collaborative Lifecycle Management, specifically versions 4.0.0 through 6.0.2.
What can an attacker do if CVE-2016-6061 is exploited?
If exploited, CVE-2016-6061 allows an attacker to embed arbitrary JavaScript code in the Web UI, potentially leading to unauthorized actions or credential disclosure.
Is CVE-2016-6061 remotely exploitable?
Yes, CVE-2016-6061 can be remotely exploited since it allows unauthorized code execution through the Web UI of impacted systems.