CVE-2017-1164: XSS
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123036.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1164?
CVE-2017-1164 is classified as a Medium severity vulnerability.
How do I fix CVE-2017-1164?
To fix CVE-2017-1164, upgrade to IBM Collaborative Lifecycle Management versions that have mitigations for cross-site scripting.
What software is affected by CVE-2017-1164?
CVE-2017-1164 affects specific versions of IBM Rational Collaborative Lifecycle Management, including versions 4.0 to 6.0.4.
What kind of exploit is associated with CVE-2017-1164?
CVE-2017-1164 allows attackers to execute arbitrary JavaScript within the web application, potentially leading to credential disclosure.
Is CVE-2017-1164 present in the latest versions of IBM software?
CVE-2017-1164 is not present in the most recent releases of IBM Collaborative Lifecycle Management following security patches.