IBM Rhapsody DM Multiple Cross Site Scripting and Open Redirection Vulnerabilities
BID:100480
Info
IBM Rhapsody DM Multiple Cross Site Scripting and Open Redirection Vulnerabilities
| Bugtraq ID: | 100480 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-1245 CVE-2017-1249 CVE-2017-1287 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2017 12:00AM |
| Updated: | Jul 20 2017 12:00AM |
| Credit: | IBM. |
| Vulnerable: |
IBM Rational Rhapsody Design Manager 6.0.3 IBM Rational Rhapsody Design Manager 6.0.2 IBM Rational Rhapsody Design Manager 6.0.1 IBM Rational Rhapsody Design Manager 5.0.2 IBM Rational Rhapsody Design Manager 5.0.1 IBM Rational Rhapsody Design Manager 6.0 IBM Rational Rhapsody Design Manager 5.0 |
| Not Vulnerable: |
IBM Rational Rhapsody Design Manager 6.0.4 |
Discussion
IBM Rhapsody DM Multiple Cross Site Scripting and Open Redirection Vulnerabilities
IBM Rhapsody DM is prone to multiple cross-site scripting and an open-redirection vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and steal cookie-based authentication credentials, or craft a URI and entice a user to follow the link to redirect victim to an attacker-controlled site and conduct phishing attacks.
IBM Rhapsody DM 5.0.0 through 5.0.2 and 6.0 through 6.0.3 are vulnerable.
IBM Rhapsody DM is prone to multiple cross-site scripting and an open-redirection vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and steal cookie-based authentication credentials, or craft a URI and entice a user to follow the link to redirect victim to an attacker-controlled site and conduct phishing attacks.
IBM Rhapsody DM 5.0.0 through 5.0.2 and 6.0 through 6.0.3 are vulnerable.
References
IBM Rhapsody DM Multiple Cross Site Scripting and Open Redirection Vulnerabilities
References:
References: