Vulnerability CVE-2017-1629


Published: 2018-03-23

Description:
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133127.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

Vendor: IBM
Product: Rational doors next generation 
Version:
6.0.4
6.0.3
6.0.2
6.0.1
6.0.0
5.0.2
5.0.1
5.0.0
5.0
4.0.7
4.0.6
4.0.5
4.0.4
4.0.3
4.0.2
See more versions on NVD
Product: Rational team concert 
Version:
6.0.4
6.0.3
6.0.1
6.0.0
6.0
5.0.2
5.0.1
5.0.0
5.0
4.0.7
4.0.6
4.0.5
4.0.4
4.0.3
See more versions on NVD
Product: Rational rhapsody design manager 
Version:
6.0.4
6.0.3
6.0.2
6.0.1
6.0.0
6.0
5.0.2
5.0.1
5.0.0
5.0
4.0.7
4.0.6
4.0.5
4.0.4
4.0.3
4.0.2
See more versions on NVD
Product: Rational quality manager 
Version:
6.0.4
6.0.3
6.0.2
6.0.1
6.0.0
6.0
5.0.2
5.0.1
5.0.0
5.0
4.0.7
4.0.6
4.0.5
4.0.4
4.0.3
See more versions on NVD
Product: Rational engineering lifecycle manager 
Version:
6.0.3
6.0.2
6.0.1
6.0.0
6.0
5.0.2
5.0.1
5.0.0
5.0
4.0.7
4.0.6
4.0.5
4.0.4
4.0.3
See more versions on NVD
Product: Rational collaborative lifecycle management 
Version:
6.0.3
6.0.1
6.0.0
6.0
5.0.2
5.0.1
5.0.0
5.0
4.0.7
4.0.6
4.0.5
4.0.4
4.0.3
4.0.2
See more versions on NVD
Product: Rational software architect design manager 
Version:
6.0.1
6.0.0
5.0.2
5.0.1
5.0.0
5.0
4.0.7
4.0.6
4.0.5
4.0.4
4.0.3
4.0.2
See more versions on NVD

CVSS2 => (AV:N/AC:M/Au:S/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.5/10
2.9/10
6.8/10
Exploit range
Attack complexity
Authentication
Remote
Medium
Single time
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None

 References:
http://www.ibm.com/support/docview.wss?uid=swg22014815
http://www.securityfocus.com/bid/103477
https://exchange.xforce.ibmcloud.com/vulnerabilities/133127

Related CVE
CVE-2019-4203
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially carry out SSRF attacks. IBM X-Force ID: 159124.
CVE-2019-4202
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitrary code on the server and gain complete access to the system. IBM X-Force ID: 159123.
CVE-2019-4178
IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to write or view arbitrary files on the system. IBM X-Force ID: 158919.
CVE-2019-4012
IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-en...
CVE-2018-1925
IBM WebShere MQ 9.1.0.0, 9.1.0.1, 9.1.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 152925.
CVE-2019-4013
IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code execution on underlying system with root privileges. IBM X-Force ID: 155887.
CVE-2018-1994
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-F...
CVE-2018-1903
IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, and 6.0.0 could allow a user with restricted sudo access on a system to manipulate CD UNIX to gain full sudo access. IBM X-Force ID: 152532.

Copyright 2019, cxsecurity.com

 

Back to Top