Vulnerability Name: CVE-2016-2926 (CCN-113363) Assigned: 2016-11-03 Published: 2016-11-03 Updated: 2017-07-28 Summary: Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Team Concert 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. CVSS v3 Severity: 5.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N )5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): LowUser Interaction (UI): RequiredScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): None
5.4 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N )5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): LowUser Interaction (UI): RequiredScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-79 Vulnerability Consequences: Cross-Site Scripting References: Source: MITRE Type: CNACVE-2016-2926 Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www-01.ibm.com/support/docview.wss?uid=swg21993444 Source: CCN Type: IBM Security Bulletin 1993444 (Rational Collaborative Lifecycle Management)Cross-site scripting vulnerability affects multiple IBM Rational products based on IBM Jazz technology (CVE-2016-2926) Source: BID Type: UNKNOWN94146 Source: CCN Type: BID-94146Multiple IBM Rational Products CVE-2016-2926 Cross Site Scripting Vulnerability Source: SECTRACK Type: UNKNOWN1037276 Source: SECTRACK Type: UNKNOWN1037277 Source: SECTRACK Type: UNKNOWN1037278 Source: SECTRACK Type: UNKNOWN1037279 Source: XF Type: UNKNOWNibm-jazz-cve20162926-xss(113363) Vulnerable Configuration: Configuration 1 :cpe:/a:ibm:rational_team_concert:3.0.1.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:5.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:5.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:6.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:6.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:6.0.2:*:*:*:*:*:*:* Configuration 2 :cpe:/a:ibm:rational_rhapsody_design_manager:4.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:4.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:4.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:4.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:4.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:4.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:4.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:4.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:5.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:5.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:6.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:6.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:6.0.2:*:*:*:*:*:*:* Configuration 3 :cpe:/a:ibm:rational_engineering_lifecycle_manager:4.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:4.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:4.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:4.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:4.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:4.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:4.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:4.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:5.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:5.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:6.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:6.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:6.0.2:*:*:*:*:*:*:* Configuration 4 :cpe:/a:ibm:rational_quality_manager:3.0.1.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:5.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:5.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:6.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:6.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:6.0.2:*:*:*:*:*:*:* Configuration 5 :cpe:/a:ibm:rational_collaborative_lifecycle_management:3.0.1.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:5.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:5.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:6.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:6.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:6.0.2:*:*:*:*:*:*:* Configuration 6 :cpe:/a:ibm:rational_software_architect_design_manager:4.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:4.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:4.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:4.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:4.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:4.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:4.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:4.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:5.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:5.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:6.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:6.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:6.0.2:*:*:*:*:*:*:* Configuration 7 :cpe:/a:ibm:rational_doors_next_generation:4.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:4.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:4.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:4.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:4.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:4.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:4.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:4.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:5.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:5.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:6.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:6.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:6.0.2:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:5.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:5.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:6.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:6.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:6.0.2:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
ibm rational team concert 3.0.1.6
ibm rational team concert 4.0.0
ibm rational team concert 4.0.1
ibm rational team concert 4.0.2
ibm rational team concert 4.0.3
ibm rational team concert 4.0.4
ibm rational team concert 4.0.5
ibm rational team concert 4.0.6
ibm rational team concert 4.0.7
ibm rational team concert 5.0.0
ibm rational team concert 5.0.1
ibm rational team concert 5.0.2
ibm rational team concert 6.0.0
ibm rational team concert 6.0.1
ibm rational team concert 6.0.2
ibm rational rhapsody design manager 4.0
ibm rational rhapsody design manager 4.0.1
ibm rational rhapsody design manager 4.0.2
ibm rational rhapsody design manager 4.0.3
ibm rational rhapsody design manager 4.0.4
ibm rational rhapsody design manager 4.0.5
ibm rational rhapsody design manager 4.0.6
ibm rational rhapsody design manager 4.0.7
ibm rational rhapsody design manager 5.0.0
ibm rational rhapsody design manager 5.0.1
ibm rational rhapsody design manager 5.0.2
ibm rational rhapsody design manager 6.0.0
ibm rational rhapsody design manager 6.0.1
ibm rational rhapsody design manager 6.0.2
ibm rational engineering lifecycle manager 4.0.0
ibm rational engineering lifecycle manager 4.0.1
ibm rational engineering lifecycle manager 4.0.2
ibm rational engineering lifecycle manager 4.0.3
ibm rational engineering lifecycle manager 4.0.4
ibm rational engineering lifecycle manager 4.0.5
ibm rational engineering lifecycle manager 4.0.6
ibm rational engineering lifecycle manager 4.0.7
ibm rational engineering lifecycle manager 5.0.0
ibm rational engineering lifecycle manager 5.0.1
ibm rational engineering lifecycle manager 5.0.2
ibm rational engineering lifecycle manager 6.0.0
ibm rational engineering lifecycle manager 6.0.1
ibm rational engineering lifecycle manager 6.0.2
ibm rational quality manager 3.0.1.6
ibm rational quality manager 4.0.0
ibm rational quality manager 4.0.1
ibm rational quality manager 4.0.2
ibm rational quality manager 4.0.3
ibm rational quality manager 4.0.4
ibm rational quality manager 4.0.5
ibm rational quality manager 4.0.6
ibm rational quality manager 4.0.7
ibm rational quality manager 5.0.0
ibm rational quality manager 5.0.1
ibm rational quality manager 5.0.2
ibm rational quality manager 6.0.0
ibm rational quality manager 6.0.1
ibm rational quality manager 6.0.2
ibm rational collaborative lifecycle management 3.0.1.6
ibm rational collaborative lifecycle management 4.0.0
ibm rational collaborative lifecycle management 4.0.1
ibm rational collaborative lifecycle management 4.0.2
ibm rational collaborative lifecycle management 4.0.3
ibm rational collaborative lifecycle management 4.0.4
ibm rational collaborative lifecycle management 4.0.5
ibm rational collaborative lifecycle management 4.0.6
ibm rational collaborative lifecycle management 4.0.7
ibm rational collaborative lifecycle management 5.0.0
ibm rational collaborative lifecycle management 5.0.1
ibm rational collaborative lifecycle management 5.0.2
ibm rational collaborative lifecycle management 6.0.0
ibm rational collaborative lifecycle management 6.0.1
ibm rational collaborative lifecycle management 6.0.2
ibm rational software architect design manager 4.0.0
ibm rational software architect design manager 4.0.1
ibm rational software architect design manager 4.0.2
ibm rational software architect design manager 4.0.3
ibm rational software architect design manager 4.0.4
ibm rational software architect design manager 4.0.5
ibm rational software architect design manager 4.0.6
ibm rational software architect design manager 4.0.7
ibm rational software architect design manager 5.0.0
ibm rational software architect design manager 5.0.1
ibm rational software architect design manager 5.0.2
ibm rational software architect design manager 6.0.0
ibm rational software architect design manager 6.0.1
ibm rational software architect design manager 6.0.2
ibm rational doors next generation 4.0.0
ibm rational doors next generation 4.0.1
ibm rational doors next generation 4.0.2
ibm rational doors next generation 4.0.3
ibm rational doors next generation 4.0.4
ibm rational doors next generation 4.0.5
ibm rational doors next generation 4.0.6
ibm rational doors next generation 4.0.7
ibm rational doors next generation 5.0.0
ibm rational doors next generation 5.0.1
ibm rational doors next generation 5.0.2
ibm rational doors next generation 6.0.0
ibm rational doors next generation 6.0.1
ibm rational doors next generation 6.0.2
ibm rational collaborative lifecycle management 4.0
ibm rational collaborative lifecycle management 4.0.1
ibm rational collaborative lifecycle management 4.0.2
ibm rational collaborative lifecycle management 4.0.3
ibm rational collaborative lifecycle management 4.0.4
ibm rational collaborative lifecycle management 4.0.5
ibm rational collaborative lifecycle management 4.0.6
ibm rational collaborative lifecycle management 5.0
ibm rational collaborative lifecycle management 4.0.7
ibm rational collaborative lifecycle management 5.0.1
ibm rational collaborative lifecycle management 5.0.2
ibm rational collaborative lifecycle management 6.0
ibm rational collaborative lifecycle management 6.0.1
ibm rational collaborative lifecycle management 6.0.2