VYPR
Unrated severityNVD Advisory· Published Jul 6, 2018· Updated Sep 17, 2024

CVE-2017-1329

CVE-2017-1329

Description

IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 126231.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Rational Quality Manager (RQM) versions 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection, allowing remote attackers to inject malicious HTML code executed in the victim's browser.

Vulnerability

IBM Quality Manager (RQM) versions 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection [1]. The vulnerability allows a remote attacker to inject malicious HTML code into the application. The affected versions are explicitly listed in the advisory.

Exploitation

An attacker needs low-privileged access (PR:L) and user interaction (UI:R) to exploit this vulnerability [1]. The attacker can inject HTML code that, when viewed by a victim, executes in the victim's browser within the security context of the hosting site. The attack vector is network (AV:N) with low complexity (AC:L) [1].

Impact

Successful exploitation leads to limited impact on confidentiality and integrity (C:L/I:L) [1]. The attacker can execute arbitrary HTML in the victim's browser, potentially altering the intended functionality or leading to credential disclosure within a trusted session. The scope is changed (S:C) meaning the impact extends beyond the vulnerable component [1].

Mitigation

IBM has released a fix as part of IBM Rational Quality Manager 6.0.5.1 or later [1]. Users should upgrade to the latest version. No workaround is mentioned in the advisory. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.