An undisclosed security vulnerability of IBM Rational DOORS Next Generation and Rational Requirements Composer may result in a Cross Site Scripting attack.
CVEID: CVE-2016-0243**
Description:** IBM Active Content Filtering is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victimβs Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victimβs cookie-based authentication credentials.
CVSS Base Score: 6.1 **CVSS Temporal Score:**See https://exchange.xforce.ibmcloud.com/vulnerabilities/110444 for the current score *CVSS Environmental Score:**Undefined CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Rational Requirements Composer 4.0 - 4.0.7
Rational DOORS Next Generation 4.0.1 - 4.0.7
Rational DOORS Next Generation 5.0 - 5.0.2
Rational DOORS Next Generation 6.0 - 6.0.1
For the 6.x releases upgrade to version 6.0.1 iFix003.
For the 5.x releases upgrade to version 5.0.2 iFix014.
For the 4.x releases upgrade to version 4.0.7 iFix010.
None