CVE-2017-1100: XSS
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120661.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1100?
CVE-2017-1100 is classified as a moderate severity vulnerability due to its potential to lead to cross-site scripting and credentials disclosure.
How do I fix CVE-2017-1100?
To fix CVE-2017-1100, upgrade IBM Rational Quality Manager to a version that addresses the cross-site scripting vulnerability.
What software versions are affected by CVE-2017-1100?
CVE-2017-1100 affects IBM Rational Quality Manager versions 4.0 through 6.0.
What type of attack does CVE-2017-1100 enable?
CVE-2017-1100 enables attackers to execute arbitrary JavaScript code through cross-site scripting in the affected software.
Is user authentication affected by CVE-2017-1100?
Yes, CVE-2017-1100 can lead to credential disclosure within a trusted session, potentially compromising user authentication.