Zero-Day Advisory
Fortinet Discovers IBM Rational Collaborative Lifecycle Management Cross-Site Scripting Vulnerability
Summary
Fortinet's FortiGuard Labs has discovered a cross-site scripting vulnerability in IBM Rational Collaborative Lifecycle Management.
IBM Rational Collaborative Lifecycle Management is an application lifecycle management solution that includes IBM Rational Team Concert, IBM Rational DOORS Next Generation and IBM Rational Quality Manager products.
The cross-site scripting vulnerability is caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
Solutions
FortiGuard Labs released the following FortiGate IPS signature which covers this specific vulnerability:IBM.Collaborative.Lifecycle.Management.XSS
Released Jun 01, 2016
FortiWeb can cover this specific vulnerability with following signature category:
Cross Site Scripting
Users should apply the solution provided by IBM.
Additional Information
Following are the products which are affected by this vulnerability.
IBM Rational Collaborative Lifecycle Management 4.0
IBM Rational Collaborative Lifecycle Management 3.0.1.6
IBM Rational Collaborative Lifecycle Management 4.0.1
IBM Rational Collaborative Lifecycle Management 4.0.2
IBM Rational Collaborative Lifecycle Management 4.0.3
IBM Rational Collaborative Lifecycle Management 4.0.4
IBM Rational Collaborative Lifecycle Management 4.0.5
IBM Rational Collaborative Lifecycle Management 4.0.6
IBM Rational Collaborative Lifecycle Management 5.0
IBM Rational Collaborative Lifecycle Management 4.0.7
IBM Rational Collaborative Lifecycle Management 5.0.1
IBM Rational Collaborative Lifecycle Management 5.0.2
IBM Rational Collaborative Lifecycle Management 6.0
IBM Rational Collaborative Lifecycle Management 6.0.1
IBM Rational Collaborative Lifecycle Management 6.0.2
References
Acknowledgement
This vulnerability was discovered by Honggang Ren of Fortinet's FortiGuard Labs.