CVE-2017-1127: XSS
IBM Rational DOORS Next Generation 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1127?
The severity of CVE-2017-1127 is considered high due to its potential to lead to credential disclosure.
How do I fix CVE-2017-1127?
To fix CVE-2017-1127, apply the latest security patches and updates provided by IBM for the affected versions of Rational DOORS Next Generation and Rational Requirements Composer.
What systems are affected by CVE-2017-1127?
CVE-2017-1127 affects IBM Rational DOORS Next Generation versions 4.0, 5.0, and 6.0, as well as IBM Rational Requirements Composer version 4.0.
What type of vulnerability is CVE-2017-1127?
CVE-2017-1127 is a cross-site scripting (XSS) vulnerability that allows embedding of arbitrary JavaScript code.
What impact does CVE-2017-1127 have on users?
The impact of CVE-2017-1127 includes the potential for attackers to execute scripts in the context of a user's session, leading to data theft or manipulation.