CVE-2017-1562: XSS
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131761.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1562?
CVE-2017-1562 is a medium severity vulnerability allowing for cross-site scripting in affected IBM products.
How do I fix CVE-2017-1562?
To fix CVE-2017-1562, upgrade to the latest patched version of IBM Rational Quality Manager or IBM Rational Collaborative Lifecycle Management.
What software versions are affected by CVE-2017-1562?
CVE-2017-1562 affects IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management versions 5.0 through 5.0.2 and 6.0 through 6.0.5.
What is the impact of exploiting CVE-2017-1562?
Exploiting CVE-2017-1562 allows attackers to embed arbitrary JavaScript code, potentially altering the intended functionality of the web interface.
Is my organization at risk for CVE-2017-1562?
If you are using any affected versions of IBM Rational Quality Manager or IBM Rational Collaborative Lifecycle Management, your organization is at risk for CVE-2017-1562.