CVE-2015-7471
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Team Concert (RTC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Requirements Composer (RRC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1 and 4.0.x before 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6, and 4.0.7 before iFix10, 5.0.x before 5.0.2 iFix1, and 6.0.x before 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; and Rational Software Architect Design Manager (RSA DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4 allows remote authenticated users with project administrator privileges to inject arbitrary web script or HTML via a crafted project. IBM X-Force ID: 108429.
Vulnerabilidad Cross-Site Scripting (XSS) en IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 anteriores a 3.0.1.6 iFix7 Interim Fix 1, 4.0.x anteriores a 4.0.7 iFix10, 5.0.x anteriores a 5.0.2 iFix15 y 6.0.x anteriores a 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x anteriores a 3.0.1.6 iFix7 Interim Fix 1, 4.0.x anteriores a 4.0.7 iFix10, 5.0.x anteriores a 5.0.2 iFix15 y 6.0.x anteriores a 6.0.1 iFix4; Rational Team Concert (RTC) 3.0.x anteriores a 3.0.1.6 iFix7 Interim Fix 1, 4.0.x anteriores a 4.0.7 iFix10, 5.0.x anteriores a 5.0.2 iFix15 y 6.0.x anteriores a 6.0.1 iFix4; Rational Requirements Composer (RRC) 3.0.x anteriores a 3.0.1.6 iFix7 Interim Fix 1 and 4.0.x anteriores a 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x anteriores a 4.0.7 iFix10, 5.0.x anteriores a 5.0.2 iFix15 y 6.0.x anteriores a 6.0.1 iFix4; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6 y 4.0.7 anteriores a iFix10, 5.0.x anteriores a 5.0.2 iFix1 y 6.0.x anteriores a 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x anteriores a 4.0.7 iFix10, 5.0.x anteriores a 5.0.2 iFix15 y 6.0.x anteriores a 6.0.1 iFix4; and Rational Software Architect Design Manager (RSA DM) 4.0.x anteriores a 4.0.7 iFix10, 5.0.x anteriores a 5.0.2 iFix15 y 6.0.x anteriores a 6.0.1 iFix4 permiten que los usuarios autenticados remotos con privilegios de administrador del proyecto inyecten scripts web o HTML arbitrarios mediante un proyecto manipulado. IBM X-Force ID: 108429.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-09-29 CVE Reserved
- 2018-03-15 CVE Published
- 2024-01-23 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21982747 | 2018-04-10 |
URL | Date | SRC |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/108429 | 2018-04-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Rational Collaborative Lifecycle Management Search vendor "Ibm" for product "Rational Collaborative Lifecycle Management" | >= 3.0.1 <= 6.0.1 Search vendor "Ibm" for product "Rational Collaborative Lifecycle Management" and version " >= 3.0.1 <= 6.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Quality Manager Search vendor "Ibm" for product "Rational Quality Manager" | >= 3.0 <= 3.0.1.6 Search vendor "Ibm" for product "Rational Quality Manager" and version " >= 3.0 <= 3.0.1.6" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Quality Manager Search vendor "Ibm" for product "Rational Quality Manager" | >= 4.0 <= 4.0.7 Search vendor "Ibm" for product "Rational Quality Manager" and version " >= 4.0 <= 4.0.7" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Quality Manager Search vendor "Ibm" for product "Rational Quality Manager" | 5.0 Search vendor "Ibm" for product "Rational Quality Manager" and version "5.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Quality Manager Search vendor "Ibm" for product "Rational Quality Manager" | 5.0.1 Search vendor "Ibm" for product "Rational Quality Manager" and version "5.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Quality Manager Search vendor "Ibm" for product "Rational Quality Manager" | 5.0.2 Search vendor "Ibm" for product "Rational Quality Manager" and version "5.0.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Quality Manager Search vendor "Ibm" for product "Rational Quality Manager" | 6.0 Search vendor "Ibm" for product "Rational Quality Manager" and version "6.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Quality Manager Search vendor "Ibm" for product "Rational Quality Manager" | 6.0.1 Search vendor "Ibm" for product "Rational Quality Manager" and version "6.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | >= 3.0 <= 3.0.6 Search vendor "Ibm" for product "Rational Team Concert" and version " >= 3.0 <= 3.0.6" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | >= 4.0 <= 4.0.7 Search vendor "Ibm" for product "Rational Team Concert" and version " >= 4.0 <= 4.0.7" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 5.0 Search vendor "Ibm" for product "Rational Team Concert" and version "5.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 5.0.1 Search vendor "Ibm" for product "Rational Team Concert" and version "5.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 5.0.2 Search vendor "Ibm" for product "Rational Team Concert" and version "5.0.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 6.0 Search vendor "Ibm" for product "Rational Team Concert" and version "6.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 6.0.1 Search vendor "Ibm" for product "Rational Team Concert" and version "6.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Requirements Composer Search vendor "Ibm" for product "Rational Requirements Composer" | >= 3.0 <= 3.0.1.6 Search vendor "Ibm" for product "Rational Requirements Composer" and version " >= 3.0 <= 3.0.1.6" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Requirements Composer Search vendor "Ibm" for product "Rational Requirements Composer" | >= 4.0 <= 4.0.7 Search vendor "Ibm" for product "Rational Requirements Composer" and version " >= 4.0 <= 4.0.7" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Doors Next Generation Search vendor "Ibm" for product "Rational Doors Next Generation" | >= 4.0 <= 4.0.7 Search vendor "Ibm" for product "Rational Doors Next Generation" and version " >= 4.0 <= 4.0.7" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Doors Next Generation Search vendor "Ibm" for product "Rational Doors Next Generation" | 5.0 Search vendor "Ibm" for product "Rational Doors Next Generation" and version "5.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Doors Next Generation Search vendor "Ibm" for product "Rational Doors Next Generation" | 5.0.1 Search vendor "Ibm" for product "Rational Doors Next Generation" and version "5.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Doors Next Generation Search vendor "Ibm" for product "Rational Doors Next Generation" | 5.0.2 Search vendor "Ibm" for product "Rational Doors Next Generation" and version "5.0.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Doors Next Generation Search vendor "Ibm" for product "Rational Doors Next Generation" | 6.0.0 Search vendor "Ibm" for product "Rational Doors Next Generation" and version "6.0.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Doors Next Generation Search vendor "Ibm" for product "Rational Doors Next Generation" | 6.0.1 Search vendor "Ibm" for product "Rational Doors Next Generation" and version "6.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Engineering Lifecycle Manager Search vendor "Ibm" for product "Rational Engineering Lifecycle Manager" | >= 4.0.3 <= 4.0.7 Search vendor "Ibm" for product "Rational Engineering Lifecycle Manager" and version " >= 4.0.3 <= 4.0.7" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Engineering Lifecycle Manager Search vendor "Ibm" for product "Rational Engineering Lifecycle Manager" | 5.0 Search vendor "Ibm" for product "Rational Engineering Lifecycle Manager" and version "5.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Engineering Lifecycle Manager Search vendor "Ibm" for product "Rational Engineering Lifecycle Manager" | 5.0.1 Search vendor "Ibm" for product "Rational Engineering Lifecycle Manager" and version "5.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Engineering Lifecycle Manager Search vendor "Ibm" for product "Rational Engineering Lifecycle Manager" | 5.0.2 Search vendor "Ibm" for product "Rational Engineering Lifecycle Manager" and version "5.0.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Engineering Lifecycle Manager Search vendor "Ibm" for product "Rational Engineering Lifecycle Manager" | 6.0 Search vendor "Ibm" for product "Rational Engineering Lifecycle Manager" and version "6.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Engineering Lifecycle Manager Search vendor "Ibm" for product "Rational Engineering Lifecycle Manager" | 6.0.1 Search vendor "Ibm" for product "Rational Engineering Lifecycle Manager" and version "6.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Rhapsody Design Manager Search vendor "Ibm" for product "Rational Rhapsody Design Manager" | >= 4.0 <= 4.0.7 Search vendor "Ibm" for product "Rational Rhapsody Design Manager" and version " >= 4.0 <= 4.0.7" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Rhapsody Design Manager Search vendor "Ibm" for product "Rational Rhapsody Design Manager" | 5.0 Search vendor "Ibm" for product "Rational Rhapsody Design Manager" and version "5.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Rhapsody Design Manager Search vendor "Ibm" for product "Rational Rhapsody Design Manager" | 5.0.1 Search vendor "Ibm" for product "Rational Rhapsody Design Manager" and version "5.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Rhapsody Design Manager Search vendor "Ibm" for product "Rational Rhapsody Design Manager" | 5.0.2 Search vendor "Ibm" for product "Rational Rhapsody Design Manager" and version "5.0.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Rhapsody Design Manager Search vendor "Ibm" for product "Rational Rhapsody Design Manager" | 6.0 Search vendor "Ibm" for product "Rational Rhapsody Design Manager" and version "6.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Rhapsody Design Manager Search vendor "Ibm" for product "Rational Rhapsody Design Manager" | 6.0.1 Search vendor "Ibm" for product "Rational Rhapsody Design Manager" and version "6.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Software Architect Design Manager Search vendor "Ibm" for product "Rational Software Architect Design Manager" | >= 4.0 <= 4.0.7 Search vendor "Ibm" for product "Rational Software Architect Design Manager" and version " >= 4.0 <= 4.0.7" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Software Architect Design Manager Search vendor "Ibm" for product "Rational Software Architect Design Manager" | 5.0 Search vendor "Ibm" for product "Rational Software Architect Design Manager" and version "5.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Software Architect Design Manager Search vendor "Ibm" for product "Rational Software Architect Design Manager" | 5.0.1 Search vendor "Ibm" for product "Rational Software Architect Design Manager" and version "5.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Software Architect Design Manager Search vendor "Ibm" for product "Rational Software Architect Design Manager" | 5.0.2 Search vendor "Ibm" for product "Rational Software Architect Design Manager" and version "5.0.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Software Architect Design Manager Search vendor "Ibm" for product "Rational Software Architect Design Manager" | 6.0 Search vendor "Ibm" for product "Rational Software Architect Design Manager" and version "6.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Software Architect Design Manager Search vendor "Ibm" for product "Rational Software Architect Design Manager" | 6.0.1 Search vendor "Ibm" for product "Rational Software Architect Design Manager" and version "6.0.1" | - |
Affected
|