CVE-2017-1653: XSS
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 6.0.x) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133268.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2017-1653.
What is the severity of CVE-2017-1653?
The severity of CVE-2017-1653 is medium with a severity value of 5.4.
Which software is affected by CVE-2017-1653?
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 6.0.x), IBM Rational Quality Manager, IBM Rational Team Concert, IBM Rational DOORS Next Generation, IBM Rational Engineering Lifecycle Manager, IBM Rational Rhapsody Design Manager, IBM Rational Software Architect Design Manager 6.0, and IBM Rational Software Architect Design Manager 6.0.1 are affected by CVE-2017-1653.
What is the description of CVE-2017-1653 vulnerability?
CVE-2017-1653 is a cross-site scripting vulnerability in IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 6.0.x) that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted environment.
How can I fix CVE-2017-1653?
To fix CVE-2017-1653, apply the necessary security patches or updates provided by IBM.