CVE-2013-5404

IBM RQM <4.0.5 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other products, allows remote authenticated users to inject arbitrary web script or HTML via vectors involving an IFRAME element.

Scores

EPSS 0.0017
EPSS Percentile 37.5%

Details

CWE
CWE-79
Status published
Products (50)
ibm/rational_quality_manager
ibm/rational_quality_manager
ibm/rational_quality_manager
ibm/rational_quality_manager
ibm/rational_quality_manager
ibm/rational_quality_manager
ibm/rational_quality_manager
ibm/rational_quality_manager
ibm/rational_quality_manager
ibm/rational_quality_manager
... and 40 more
Published Dec 10, 2013
Tracked Since Feb 18, 2026