Lucene search

K
ibmIBM697E32EDBA8A1E89C8B3149BD3588E82718440765A9DFF91C12E19C40F8914B6
HistoryJun 17, 2018 - 5:27 a.m.

Security Bulletin: IBM Rational Software Architect Design Manager is vulnerable to cross-site scripting (XSS) attack (CVE-2017-1462)

2018-06-1705:27:06
www.ibm.com
11

EPSS

0.001

Percentile

33.9%

Summary

Document web editor in RSA DM could be vulnerable to cross-site scripting attack if document content was tampered.

Vulnerability Details

CVEID:CVE-2017-1462
DESCRIPTION: IBM Rhapsody DM is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. CVSS Base Score: 5.4 CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/138436 for the current score CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

IBM Rational Software Architect Design Manager 4.0.0 - 4.0.7
IBM Rational Software Architect Design Manager 5.0.0 - 5.0.2
IBM Rational Software Architect Design Manager 6.0.0 - 6.0.2

Remediation/Fixes

For IBM Rational Software Architect Design Manager version 4.0.0 - 4.0.7 contact IBM Support.

For IBM Rational Software Architect Design Manager version 5.0.0 - 5.0.1 upgrade to version 5.0.2 and apply 5.0.2 iFix011c

For IBM Rational Software Architect Design Manager version 6.0.0 - 6.0.1 upgrade to version 6.0.2 and apply 6.0.2 iFix003c.

_For other _versions of the products, IBM recommends upgrading to a fixed, supported version of the product. Please contact IBM Support with any questions.

Workarounds and Mitigations

None

EPSS

0.001

Percentile

33.9%

Related for 697E32EDBA8A1E89C8B3149BD3588E82718440765A9DFF91C12E19C40F8914B6