Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other products, allows remote authenticated users to inject arbitrary web script or HTML via vectors involving an IFRAME element.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: ibm

Published: 2013-12-10T19:00:00

Updated: 2017-08-28T12:57:01

Reserved: 2013-08-22T00:00:00


Link: CVE-2013-5404

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2013-12-10T19:55:07.297

Modified: 2017-08-29T01:33:45.747


Link: CVE-2013-5404

JSON object: View

cve-icon Redhat Information

No data.

CWE