IBM Security Bulletin: Vulnerabilities in Rational DOORS Next Generation with potential for Cross-Site Scripting and HTML Injection attacks

Undisclosed security vulnerabilities in IBM Rational DOORS Next Generation and Rational Requirements Composer may result in Cross-Site Scripting and HTML Injection attacks (CVE-2017-1247, CVE-2017-1276, CVE-2017-1278) .

CVE(s): CVE-2017-1247, CVE-2017-1276, CVE-2017-1278

Affected product(s) and affected version(s):

Rational DOORS Next Generation 6.0 – 6.0.3

Rational Requirements Composer 5.0 – 5.0.2

Rational Requirements Composer 4.0.1 – 4.0.7

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2rdjF13
X-Force Database: http://ift.tt/2rII0iS
X-Force Database: http://ift.tt/2rdDiGd
X-Force Database: http://ift.tt/2rItwzq

The post IBM Security Bulletin: Vulnerabilities in Rational DOORS Next Generation with potential for Cross-Site Scripting and HTML Injection attacks appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2rdn5kh