CVE-2017-1248
Description
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124628.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Rational Quality Manager (RQM) versions 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection, allowing remote attackers to execute arbitrary HTML in a victim's browser.
Vulnerability
IBM Quality Manager (RQM) versions 5.0.x and 6.0 through 6.0.5 are affected by an HTML injection vulnerability [1]. A remote attacker can inject malicious HTML code into the application, which, when rendered in a victim's browser, executes within the security context of the hosting site [1].
Exploitation
An attacker needs a valid account on the RQM instance (low-privileged access) and must convince a victim to view a crafted page or content containing the injected HTML [1]. The attacker can inject arbitrary HTML by sending specially crafted input that is not properly sanitized [1]. No other special privileges or network position beyond standard web access is required [1].
Impact
Successful exploitation allows the attacker to execute arbitrary HTML in the victim's browser, potentially altering page content, stealing session cookies, or redirecting the user to malicious sites [1]. The impact is limited to the user's session, with CVSS 5.4 (Medium) reflecting low confidentiality and integrity impact [1].
Mitigation
IBM released fixes for CVE-2017-1248 as part of the Rational Quality Manager 6.0.5.1 and 5.0.2.7 interim fixes (or later) [1]. Users should upgrade to these fixed versions. There is no known workaround; applying the vendor-supplied fix is the recommended mitigation [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 5.0.x, 6.0 through 6.0.5
- Range: 6.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.ibm.com/support/docview.wssmitrex_refsource_CONFIRM
- exchange.xforce.ibmcloud.com/vulnerabilities/124628mitrevdb-entryx_refsource_XF
News mentions
0No linked articles in our index yet.