First published: Tue Jul 03 2018(Updated: )
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 126231.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational Quality Manager | >=5.0<=5.0.2 | |
IBM Rational Quality Manager | >=6.0<=6.0.5 | |
IBM Rational Collaborative Lifecycle Management | >=5.0.0<=6.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection, allowing a remote attacker to inject malicious HTML code that will be executed in the victim's web browser within the security context of the hosting site.
The severity of CVE-2017-1329 is medium, with a severity value of 5.4.
An attacker can exploit the IBM Quality Manager (RQM) vulnerability by injecting malicious HTML code that will be executed in the victim's web browser.
The vulnerability affects IBM Rational Quality Manager versions 5.0.x through 6.0.5.
To mitigate the vulnerability, update IBM Rational Quality Manager to a version that is not affected by the HTML injection vulnerability.