CVE-2017-1334: XSS
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126242.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1334?
CVE-2017-1334 is classified as a cross-site scripting vulnerability which can lead to credential disclosure.
How do I fix CVE-2017-1334?
To mitigate CVE-2017-1334, it is recommended to update IBM Engineering Lifecycle Manager to a patched version that addresses the vulnerability.
What versions of IBM Engineering Lifecycle Manager are affected by CVE-2017-1334?
CVE-2017-1334 affects IBM Engineering Lifecycle Manager versions 4.0, 5.0, and 6.0.
What potential impact does CVE-2017-1334 have on users?
CVE-2017-1334 can allow attackers to embed malicious JavaScript, potentially compromising user credentials during a trusted session.
Is CVE-2017-1334 exploitable remotely?
Yes, CVE-2017-1334 can be exploited remotely through the web interface of the affected IBM products.