CVE-2017-1561
published 2018-07-03CVE-2017-1561: IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site…
PriorityP423medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.71%
49.3th percentile
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131760.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_collaborative_lifecycle_management | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7751 Mozilla: Use-after-free with content viewer listeners (MFSA 2017-16)
bugzilla·2017-06-14·CVSS 9.8
CVE-2017-7751 [CRITICAL] CVE-2017-7751 Mozilla: Use-after-free with content viewer listeners (MFSA 2017-16)
CVE-2017-7751 Mozilla: Use-after-free with content viewer listeners (MFSA 2017-16)
A use-after-free vulnerability with content viewer listeners that results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7751
Acknowledgements:
Name: the Mozilla project
Upstream: Nils
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:1440 https://access.redhat.com/errata/RHSA-2017:1440
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:1561 https://access.redhat.com/errata/RHSA-2017:1561
Bugzilla
CVE-2017-7757 Mozilla: Use-after-free in IndexedDB (MFSA 2017-16)
bugzilla·2017-06-14·CVSS 9.8
CVE-2017-7757 [CRITICAL] CVE-2017-7757 Mozilla: Use-after-free in IndexedDB (MFSA 2017-16)
CVE-2017-7757 Mozilla: Use-after-free in IndexedDB (MFSA 2017-16)
A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7757
Acknowledgements:
Name: the Mozilla project
Upstream: F. Alonso (revskills)
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:1440 https://access.redhat.com/errata/RHSA-2017:1440
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:1561 https://access.redhat.com/errata/RHS
Bugzilla
CVE-2017-7756 Mozilla: Use-after-free and use-after-scope logging XHR header errors (MFSA 2017-16)
bugzilla·2017-06-14·CVSS 9.8
CVE-2017-7756 [CRITICAL] CVE-2017-7756 Mozilla: Use-after-free and use-after-scope logging XHR header errors (MFSA 2017-16)
CVE-2017-7756 Mozilla: Use-after-free and use-after-scope logging XHR header errors (MFSA 2017-16)
A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7756
Acknowledgements:
Name: the Mozilla project
Upstream: Abhishek Arya
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:1440 https://access.redhat.com/errata/RHSA-2017:1440
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:1561 https://access.redhat.com/erra
Bugzilla
CVE-2017-7750 Mozilla: Use-after-free with track elements (MFSA 2017-16)
bugzilla·2017-06-14·CVSS 9.8
CVE-2017-7750 [CRITICAL] CVE-2017-7750 Mozilla: Use-after-free with track elements (MFSA 2017-16)
CVE-2017-7750 Mozilla: Use-after-free with track elements (MFSA 2017-16)
A use-after-free vulnerability during video control operations when a element holds a reference to an older window if that window has been replaced in the DOM. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7750
Acknowledgements:
Name: the Mozilla project
Upstream: Nils
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:1440 https://access.redhat.com/errata/RHSA-2017:1440
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:1561 https://access.redhat.c
Bugzilla
CVE-2017-7749 Mozilla: Use-after-free during docshell reloading (MFSA 2017-16)
bugzilla·2017-06-14·CVSS 9.8
CVE-2017-7749 [CRITICAL] CVE-2017-7749 Mozilla: Use-after-free during docshell reloading (MFSA 2017-16)
CVE-2017-7749 Mozilla: Use-after-free during docshell reloading (MFSA 2017-16)
A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7749
Acknowledgements:
Name: the Mozilla project
Upstream: Nils
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:1440 https://access.redhat.com/errata/RHSA-2017:1440
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:1561 https://access.redhat.com/errata/RHSA-2017:1561
Bugzilla
CVE-2017-7758 Mozilla: Out-of-bounds read in Opus encoder (MFSA 2017-16)
bugzilla·2017-06-14·CVSS 9.1
CVE-2017-7758 [CRITICAL] CVE-2017-7758 Mozilla: Out-of-bounds read in Opus encoder (MFSA 2017-16)
CVE-2017-7758 Mozilla: Out-of-bounds read in Opus encoder (MFSA 2017-16)
An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7758
Acknowledgements:
Name: the Mozilla project
Upstream: Nicolas Trippar (Zimperium zLabs)
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:1440 https://access.redhat.com/errata/RHSA-2017:1440
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:1561 https://access.redhat.com/errata/RHSA-2017:1561
Bugzilla
CVE-2017-7754 Mozilla: Out-of-bounds read in WebGL with ImageInfo object (MFSA 2017-16)
bugzilla·2017-06-14·CVSS 7.5
CVE-2017-7754 [HIGH] CVE-2017-7754 Mozilla: Out-of-bounds read in WebGL with ImageInfo object (MFSA 2017-16)
CVE-2017-7754 Mozilla: Out-of-bounds read in WebGL with ImageInfo object (MFSA 2017-16)
An out-of-bounds read in WebGL with a maliciously crafted ImageInfo object during WebGL operations.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7754
Acknowledgements:
Name: the Mozilla project
Upstream: Nils
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:1440 https://access.redhat.com/errata/RHSA-2017:1440
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:1561 https://access.redhat.com/errata/RHSA-2017:1561
2018-07-03
Published