Arbitrary Script Injection in IBM Rational ClearQuest 7.1.x Web Client File Upload Functionality

Arbitrary Script Injection in IBM Rational ClearQuest 7.1.x Web Client File Upload Functionality

CVE-2012-2169 · LOW Severity

AV:N/AC:M/AU:S/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in the file-upload functionality in the Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 allows remote authenticated users to inject arbitrary web script or HTML via the File Description field.

Learn more about our Cis Benchmark Audit For Ibm I.