Vulnerability Details CVE-2015-0130
Cross-site scripting (XSS) vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Quality Manager (RQM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Team Concert (RTC) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Requirements Composer (RRC) 4.x through 4.0.7; and Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.4%
CVSS Severity
CVSS v2 Score 3.5
Products affected by CVE-2015-0130
-
cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.0
-
cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.1
-
cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.2
-
cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.3
-
cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.4
-
cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.5
-
cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.6
-
cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.7
-
cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.0
-
cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.1
-
cpe:2.3:a:ibm:rational_doors_next_generation:4.0.0
-
cpe:2.3:a:ibm:rational_doors_next_generation:4.0.1
-
cpe:2.3:a:ibm:rational_doors_next_generation:4.0.2
-
cpe:2.3:a:ibm:rational_doors_next_generation:4.0.3
-
cpe:2.3:a:ibm:rational_doors_next_generation:4.0.4
-
cpe:2.3:a:ibm:rational_doors_next_generation:4.0.5
-
cpe:2.3:a:ibm:rational_doors_next_generation:4.0.6
-
cpe:2.3:a:ibm:rational_doors_next_generation:4.0.7
-
cpe:2.3:a:ibm:rational_doors_next_generation:5.0.0
-
cpe:2.3:a:ibm:rational_doors_next_generation:5.0.1
-
cpe:2.3:a:ibm:rational_quality_manager:4.0
-
cpe:2.3:a:ibm:rational_quality_manager:4.0.0.1
-
cpe:2.3:a:ibm:rational_quality_manager:4.0.0.2
-
cpe:2.3:a:ibm:rational_quality_manager:4.0.1
-
cpe:2.3:a:ibm:rational_quality_manager:4.0.2
-
cpe:2.3:a:ibm:rational_quality_manager:4.0.3
-
cpe:2.3:a:ibm:rational_quality_manager:4.0.4
-
cpe:2.3:a:ibm:rational_quality_manager:4.0.5
-
cpe:2.3:a:ibm:rational_quality_manager:4.0.7
-
cpe:2.3:a:ibm:rational_quality_manager:5.0.0
-
cpe:2.3:a:ibm:rational_quality_manager:5.0.1
-
cpe:2.3:a:ibm:rational_requirements_composer:4.0.0
-
cpe:2.3:a:ibm:rational_requirements_composer:4.0.0.1
-
cpe:2.3:a:ibm:rational_requirements_composer:4.0.0.2
-
cpe:2.3:a:ibm:rational_requirements_composer:4.0.1
-
cpe:2.3:a:ibm:rational_requirements_composer:4.0.2
-
cpe:2.3:a:ibm:rational_requirements_composer:4.0.3
-
cpe:2.3:a:ibm:rational_requirements_composer:4.0.4
-
cpe:2.3:a:ibm:rational_requirements_composer:4.0.5
-
cpe:2.3:a:ibm:rational_requirements_composer:4.0.6
-
cpe:2.3:a:ibm:rational_requirements_composer:4.0.7
-
cpe:2.3:a:ibm:rational_team_concert:4.0
-
cpe:2.3:a:ibm:rational_team_concert:4.0.0.1
-
cpe:2.3:a:ibm:rational_team_concert:4.0.0.2
-
cpe:2.3:a:ibm:rational_team_concert:4.0.1
-
cpe:2.3:a:ibm:rational_team_concert:4.0.2
-
cpe:2.3:a:ibm:rational_team_concert:4.0.3
-
cpe:2.3:a:ibm:rational_team_concert:4.0.4
-
cpe:2.3:a:ibm:rational_team_concert:4.0.5
-
cpe:2.3:a:ibm:rational_team_concert:4.0.6
-
cpe:2.3:a:ibm:rational_team_concert:4.0.7
-
cpe:2.3:a:ibm:rational_team_concert:5.0.0
-
cpe:2.3:a:ibm:rational_team_concert:5.0.1