CVE-2017-1561: XSS
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131760.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1561?
CVE-2017-1561 is rated as high severity due to its potential impact on user data through cross-site scripting.
How do I fix CVE-2017-1561?
To fix CVE-2017-1561, upgrade to the latest versions of IBM Rational Quality Manager or IBM Rational Collaborative Lifecycle Management that address this vulnerability.
Which versions of IBM software are affected by CVE-2017-1561?
CVE-2017-1561 affects IBM Rational Quality Manager versions 5.0 to 5.0.2 and 6.0 to 6.0.5, as well as IBM Rational Collaborative Lifecycle Management versions 5.0 to 5.0.2 and 6.0 to 6.0.5.
What is the impact of exploiting CVE-2017-1561?
Exploiting CVE-2017-1561 allows attackers to inject arbitrary JavaScript code into the web UI, potentially compromising user sessions and leading to unauthorized actions.
Is there a workaround for CVE-2017-1561 until a fix is applied?
Currently, there are no documented workarounds for CVE-2017-1561; applying the patch or upgrade is the recommended course of action.