CVE-2017-1101: XSS
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120662.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1101?
CVE-2017-1101 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2017-1101?
To fix CVE-2017-1101, update your IBM Rational Quality Manager to the latest patched version provided by IBM.
What types of attacks can CVE-2017-1101 enable?
CVE-2017-1101 can enable attackers to execute arbitrary JavaScript code, which may lead to unauthorized access and credential disclosure.
Which versions of IBM Quality Manager are affected by CVE-2017-1101?
CVE-2017-1101 affects IBM Quality Manager versions 4.0, 5.0, and 6.0, including their subsequent minor releases.
Is there a workaround for CVE-2017-1101?
While the best approach is to apply the available patches, implementing input validation could serve as a temporary workaround for CVE-2017-1101.