CVE-2017-1791: XSS
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137036.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1791?
CVE-2017-1791 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks which can lead to user data exposure.
How do I fix CVE-2017-1791?
To mitigate CVE-2017-1791, users should upgrade IBM Rational Quality Manager to version 5.0.3 or higher for version 5.0 and to version 6.0.6 or higher for version 6.0.
Which versions of IBM Rational Quality Manager are affected by CVE-2017-1791?
CVE-2017-1791 affects IBM Rational Quality Manager versions 5.0 through 5.0.2 and versions 6.0 through 6.0.5.
What can attackers achieve through CVE-2017-1791?
Attackers exploiting CVE-2017-1791 can embed malicious JavaScript in the Web UI, potentially leading to credential disclosure and unauthorized actions within a trusted session.
Is user interaction required to exploit CVE-2017-1791?
Yes, exploitation of CVE-2017-1791 typically requires user interaction to trigger the cross-site scripting vulnerability.