CVE-2015-7453
Last modified
CVE-2015-7453 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Team Concert (RTC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Requirements Composer (RRC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1 and 4.0.x before 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6, and 4.0.7 before iFix10, 5.0.x before 5.0.2 iFix1, and 6.0.x before 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; and Rational Software Architect Design Manager (RSA DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108296.. EPSS estimates a 0.87% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Team Concert (RTC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Requirements Composer (RRC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1 and 4.0.x before 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6, and 4.0.7 before iFix10, 5.0.x before 5.0.2 iFix1, and 6.0.x before 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; and Rational Software Architect Design Manager (RSA DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108296.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Rational Collaborative Lifecycle Management | >= 3.0.1, <= 6.0.1 |
| Ibm | Rational Quality Manager | >= 3.0, <= 3.0.1.6 |
| Ibm | Rational Quality Manager | >= 4.0, <= 4.0.7 |
| Ibm | Rational Quality Manager | 5.0 |
| Ibm | Rational Quality Manager | 5.0.1 |
| Ibm | Rational Quality Manager | 5.0.2 |
| Ibm | Rational Quality Manager | 6.0 |
| Ibm | Rational Quality Manager | 6.0.1 |
| Ibm | Rational Team Concert | >= 3.0, <= 3.0.6 |
| Ibm | Rational Team Concert | >= 4.0, <= 4.0.7 |
| Ibm | Rational Team Concert | 5.0 |
| Ibm | Rational Team Concert | 5.0.1 |
| Ibm | Rational Team Concert | 5.0.2 |
| Ibm | Rational Team Concert | 6.0 |
| Ibm | Rational Team Concert | 6.0.1 |
| Ibm | Rational Requirements Composer | >= 3.0, <= 3.0.1.6 |
| Ibm | Rational Requirements Composer | >= 4.0, <= 4.0.7 |
| Ibm | Rational Doors Next Generation | >= 4.0, <= 4.0.7 |
| Ibm | Rational Doors Next Generation | 5.0 |
| Ibm | Rational Doors Next Generation | 5.0.1 |
| Ibm | Rational Doors Next Generation | 5.0.2 |
| Ibm | Rational Doors Next Generation | 6.0.0 |
| Ibm | Rational Doors Next Generation | 6.0.1 |
| Ibm | Rational Engineering Lifecycle Manager | >= 4.0.3, <= 4.0.7 |
| Ibm | Rational Engineering Lifecycle Manager | 5.0 |
| Ibm | Rational Engineering Lifecycle Manager | 5.0.1 |
| Ibm | Rational Engineering Lifecycle Manager | 5.0.2 |
| Ibm | Rational Engineering Lifecycle Manager | 6.0 |
| Ibm | Rational Engineering Lifecycle Manager | 6.0.1 |
| Ibm | Rational Rhapsody Design Manager | >= 4.0, <= 4.0.7 |
| Ibm | Rational Rhapsody Design Manager | 5.0 |
| Ibm | Rational Rhapsody Design Manager | 5.0.1 |
| Ibm | Rational Rhapsody Design Manager | 5.0.2 |
| Ibm | Rational Rhapsody Design Manager | 6.0 |
| Ibm | Rational Rhapsody Design Manager | 6.0.1 |
| Ibm | Rational Software Architect Design Manager | >= 4.0, <= 4.0.7 |
| Ibm | Rational Software Architect Design Manager | 5.0 |
| Ibm | Rational Software Architect Design Manager | 5.0.1 |
| Ibm | Rational Software Architect Design Manager | 5.0.2 |
| Ibm | Rational Software Architect Design Manager | 6.0 |
| Ibm | Rational Software Architect Design Manager | 6.0.1 |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21982747Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/108296VDB Entry, Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21982747Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/108296VDB Entry, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-7453?
How severe is CVE-2015-7453?
How do I fix CVE-2015-7453?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-7447IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 throu…
- CVE-2015-7448SQL injection vulnerability in IBM Maximo Asset Management 7…
- CVE-2015-7449IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x …
- CVE-2015-7450Serialized-object interfaces in certain IBM analytics, busin…9.8
- CVE-2015-7451Cross-site scripting (XSS) vulnerability in IBM Maximo Asset…
- CVE-2015-7452IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 b…
- CVE-2015-7454Business Space in IBM WebSphere Process Server 6.1.2.0 throu…
- CVE-2015-7455IBM WebSphere Portal 7.x through 7.0.0.2 CF29, 8.0.x before …
- CVE-2015-7456IBM Spectrum Scale 4.1.1 before 4.1.1.4, and 4.2.0.0, allows…
- CVE-2015-7457Cross-site scripting (XSS) vulnerability in IBM WebSphere Po…
- CVE-2015-7458Cross-site scripting (XSS) vulnerability in IBM Connections …
- CVE-2015-7459Cross-site scripting (XSS) vulnerability in IBM Connections …
Are you affected by CVE-2015-7453?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
