CVE-2017-1762: XSS
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136006.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2017-1762.
What is the severity of CVE-2017-1762?
The severity of CVE-2017-1762 is medium with a score of 5.4.
Which software versions are affected by CVE-2017-1762?
IBM Rational Collaborative Lifecycle Management versions 4.0 to 6.0.5, IBM Rational Quality Manager versions 4.0 to 6.0.5, IBM Rational Team Concert versions 4.0 to 6.0.5, IBM Rational DOORS Next Generation versions 4.0.1 to 6.0.5, IBM Rational Engineering Lifecycle Manager versions 4.0.3 to 6.0.5, IBM Rational Rhapsody Design Manager versions 4.0 to 6.0.5, and IBM Rational Software Architect Design Manager versions 4.0 to 6.0.1 are affected by CVE-2017-1762.
What is the impact of CVE-2017-1762?
CVE-2017-1762 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
Where can I find more information about CVE-2017-1762?
You can find more information about CVE-2017-1762 on the IBM Support website, SecurityFocus, and IBM X-Force Exchange.