CVE-2017-1237: XSS
IBM Jazz based applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124355.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-1237?
CVE-2017-1237 is a vulnerability in IBM Jazz based applications that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
Which IBM applications are affected by CVE-2017-1237?
IBM Rational Collaborative Lifecycle Management (versions 5.0.1 - 6.0.5), IBM Rational Team Concert (versions 5.0.1 - 6.0.5), IBM Rational DOORS Next Generation (versions 5.0.1 - 6.0.5), IBM Rational Quality Manager (versions 5.0.1 - 6.0.5), IBM Rational Rhapsody Design Manager (versions 5.0.1 - 6.0.5), IBM Rational Software Architect Design Manager (versions 5.0.1 - 6.0.1), and IBM Rational Engineering Lifecycle Manager (versions 5.0.1 - 6.0.5) are affected by CVE-2017-1237.
What is the severity of CVE-2017-1237?
CVE-2017-1237 has a severity rating of medium (5.4/10).
How do I fix CVE-2017-1237?
Apply the necessary patches provided by IBM to fix CVE-2017-1237 vulnerability in the affected applications.
Where can I find more information about CVE-2017-1237?
You can find more information about CVE-2017-1237 at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/124355) and [Reference 2](https://www-prd-trops.events.ibm.com/node/715709).