Description
IBM Team Concert (RTC including IBM Rational Collaborative Lifecycle Management 4.0, 5.0., and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 126858.
Remediation
References
Related Vulnerabilities
Lodash Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-1010266)
Ruby on Rails URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-22881)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-9015)
PHP Out-of-bounds Read Vulnerability (CVE-2020-7067)
Undertow Insertion of Sensitive Information into Log File Vulnerability (CVE-2019-3888)