IBM Security Bulletin: Cross-site scripting vulnerabilities affect IBM® Rational® Team Concert

IBM Team Concert (RTC) is vulnerable to multiple cross-site scripting vulnerabilities.

CVE(s): CVE-2016-9701, CVE-2016-9746, CVE-2016-9733, CVE-2017-1113

Affected product(s) and affected version(s):

Rational Collaborative Lifecycle Management 4.0 – 6.0.3

Rational Team Concert 4.0 – 4.0.7
Rational Team Concert 5.0 – 5.0.2
Rational Team Concert 6.0 – 6.0.3

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2tc5dsE
X-Force Database: http://ift.tt/2ss2rm2
X-Force Database: http://ift.tt/2tc5dZG
X-Force Database: http://ift.tt/2ssy66I
X-Force Database: http://ift.tt/2tc5f3K

The post IBM Security Bulletin: Cross-site scripting vulnerabilities affect IBM® Rational® Team Concert appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2ssyAtA