Rational Engineering Lifecycle Manager is vulnerable to a cross-site scripting attack with potential for credentials disclosure within a trusted session.
CVE(s): CVE-2017-1168
Affected product(s) and affected version(s):
Rational Engineering Lifecycle Manager 4.0.3 – 4.0.7
Rational Engineering Lifecycle Manager 5.0 – 5.0.2
Rational Engineering Lifecycle Manager 6.0 – 6.0.3
Note: 6.0.4 release is not affected.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2upNT3s
X-Force Database: http://ift.tt/2vOvY9X
The post IBM Security Bulletin: Cross-site Scripting vulnerability affects Rational Engineering Lifecycle Manager appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team http://ift.tt/2upNU7w
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.