CVE-2017-1324: XSS
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125975.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1324?
CVE-2017-1324 is classified as a moderate severity vulnerability due to its potential for cross-site scripting and credentials disclosure.
How do I fix CVE-2017-1324?
To fix CVE-2017-1324, you should apply the latest security patches provided by IBM for the affected versions of IBM Engineering Lifecycle Manager.
Which versions of IBM Engineering Lifecycle Manager are affected by CVE-2017-1324?
CVE-2017-1324 affects IBM Engineering Lifecycle Manager versions 4.0.3 to 6.0.4.
What type of vulnerability is CVE-2017-1324?
CVE-2017-1324 is a cross-site scripting (XSS) vulnerability allowing the embedding of arbitrary JavaScript code.
What could be the consequences of CVE-2017-1324?
The consequences of CVE-2017-1324 include potential credentials disclosure within a trusted session, which can compromise user security.