IBM Security Bulletin: Cross-site Scripting vulnerabilities affect IBM Rational products based on IBM Jazz technology

Potential Cross-site scripting vulnerabilities affect the following IBM Rational Products: Rational Engineering Lifecycle Manager (RELM), Rational Rhapsody Design Manager (Rhapsody DM)

CVE(s): CVE-2016-8975, CVE-2017-1245, CVE-2017-1249, CVE-2017-1287

Affected product(s) and affected version(s):

Rational Rhapsody Design Manager 5.0.0-5.0.2, 6.0 – 6.0.3 (Versions 6.0.4 and above are not affected)

Rational Engineering Lifecycle Manager 6.0 – 6.0.2 (Versions 6.0.3 and above are not affected)

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2uPYXe0
X-Force Database: http://ift.tt/2uhRWzq
X-Force Database: http://ift.tt/2uPZxbC
X-Force Database: http://ift.tt/2uhUr4D
X-Force Database: http://ift.tt/2uPYXL2

The post IBM Security Bulletin: Cross-site Scripting vulnerabilities affect IBM Rational products based on IBM Jazz technology appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2uik31p