VYPR
Medium severity4.8NVD Advisory· Published May 10, 2017· Updated May 13, 2026

CVE-2016-6037

CVE-2016-6037

Description

IBM Rational Team Concert (RTC) is vulnerable to HTML injection. A remote attacker with project administrator privileges could send a project that contains malicious HTML code, which when the project is viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 116918.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Rational Team Concert (RTC) is vulnerable to HTML injection, allowing a project administrator to inject malicious HTML that executes in viewers' browsers.

Vulnerability

IBM Rational Team Concert (RTC) is affected by an HTML injection vulnerability [1]. A remote attacker with project administrator privileges can craft a project containing malicious HTML code. When the project is viewed by another user, the injected HTML executes in the victim's web browser within the security context of the hosting site. The CVSS vector (AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N) indicates low confidentiality and integrity impact with a changed scope [1].

Exploitation

To exploit this vulnerability, an attacker must have project administrator privileges in RTC [1]. The attacker sends a project that includes malicious HTML code. No additional user interaction is required beyond the victim viewing the project. The malicious HTML is rendered in the victim's browser, executing within the security context of the RTC site.

Impact

Successful exploitation allows the attacker to inject arbitrary HTML into the victim's browser session [1]. This can lead to credential disclosure, session hijacking, or other actions that the victim can perform within the RTC application. The CVSS score of 4.8 (Medium) reflects the requirement for high privileges and user interaction, but the scope change means the injected content can affect resources beyond the vulnerable component.

Mitigation

IBM has released a security bulletin addressing this vulnerability [1]. Users should apply the latest updates provided by IBM for Rational Team Concert. No workarounds are documented in the available reference. Organizations should review the bulletin and apply the fix to affected installations.

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • IBM Corporation/Rational Collaborative Lifecycle Managementv5
    Range: 4.0.7, 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, 6.0.2, 6.0.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.