CVE-2016-0285
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted field.
Vulnerabilidad de XSS en IBM Rational Collaborative Lifecycle Management 3.0.1.6 en versiones anteriores a iFix8, 4.0 en versiones anteriores a 4.0.7 iFix11, 5.0 en versiones anteriores a 5.0.2 iFix18 y 6.0 en versiones anteriores a 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 en versiones anteriores a iFix8, 4.0 en versiones anteriores a 4.0.7 iFix11, 5.0 en versiones anteriores a 5.0.2 iFix18 y 6.0 en versiones anteriores a 6.0.2 iFix5; Rational Team Concert 3.0.1.6 en versiones anteriores a iFix8, 4.0 en versiones anteriores a 4.0.7 iFix11, 5.0 en versiones anteriores a 5.0.2 iFix18 y 6.0 en versiones anteriores a 6.0.2 iFix5; Rational DOORS Next Generation 4.0 en versiones anteriores a 4.0.7 iFix11, 5.0 en versiones anteriores a 5.0.2 iFix18 y 6.0 en versiones anteriores a 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x en versiones anteriores a 4.0.7 iFix11, 5.0 en versiones anteriores a 5.0.2 iFix18 y 6.0 en versiones anteriores a 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 en versiones anteriores a 4.0.7 iFix11, 5.0 en versiones anteriores a 5.0.2 iFix18 y 6.0 en versiones anteriores a 6.0.2 iFix5; y Rational Software Architect Design Manager 4.0 en versiones anteriores a 4.0.7 iFix11, 5.0 en versiones anteriores a 5.0.2 iFix18 y 6.0 en versiones anteriores a 6.0.2 iFix5 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de un campo manipulado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-12-08 CVE Reserved
- 2016-11-24 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/94550 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21991478 | 2016-11-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 3.0.1.6 Search vendor "Ibm" for product "Rational Team Concert" and version "3.0.1.6" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 4.0.0 Search vendor "Ibm" for product "Rational Team Concert" and version "4.0.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 4.0.1 Search vendor "Ibm" for product "Rational Team Concert" and version "4.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 4.0.2 Search vendor "Ibm" for product "Rational Team Concert" and version "4.0.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 4.0.3 Search vendor "Ibm" for product "Rational Team Concert" and version "4.0.3" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 4.0.4 Search vendor "Ibm" for product "Rational Team Concert" and version "4.0.4" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 4.0.5 Search vendor "Ibm" for product "Rational Team Concert" and version "4.0.5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 4.0.6 Search vendor "Ibm" for product "Rational Team Concert" and version "4.0.6" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 4.0.7 Search vendor "Ibm" for product "Rational Team Concert" and version "4.0.7" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 5.0.0 Search vendor "Ibm" for product "Rational Team Concert" and version "5.0.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 5.0.1 Search vendor "Ibm" for product "Rational Team Concert" and version "5.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 5.0.2 Search vendor "Ibm" for product "Rational Team Concert" and version "5.0.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 6.0.0 Search vendor "Ibm" for product "Rational Team Concert" and version "6.0.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 6.0.1 Search vendor "Ibm" for product "Rational Team Concert" and version "6.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Team Concert Search vendor "Ibm" for product "Rational Team Concert" | 6.0.2 Search vendor "Ibm" for product "Rational Team Concert" and version "6.0.2" | - |
Affected
|