Jazz Forum Welcome to the Jazz Community Forum Connect and collaborate with IBM Engineering experts and users

XSS issue located in ram infopop

We try the following URL in the RAM server:
https://RAMURL//cloud/enterprise/ram/infopop?contextId=sgen0101&default=Modify%3Ciframe+src%3Djavascript%3Aalert%28105486%29%3E

Then in the RAM 7202 server it will popup a window with the value : 105486
In the RAM 7511 server it will not open new window, instead show the following content:
Modify: Edit the description, categories, attached artifacts, or related assets for this asset. Depending on the current state of the asset and the edits that you make, when you modify an asset, you might change its state, move it to a different lifecycle, or trigger policies.

Please let me know if it means  this XSS issue is fixed in 7511

0 votes


Accepted answer

Permanent link
That is correct. This problem was fixed in 7.5.0.1. See defect Infopops contain an XSS vulnerability (39180).
pan tianming selected this answer as the correct answer

0 votes

Your answer

Register or log in to post your answer.

Dashboards and work items are no longer publicly available, so some links may be invalid. We now provide similar information through other means. Learn more here.

Search context
Follow this question

By Email: 

Once you sign in you will be able to subscribe for any updates here.

By RSS:

Answers
Answers and Comments
Question details
× 12,020

Question asked: Nov 21 '12, 8:56 p.m.

Question was seen: 3,711 times

Last updated: Nov 26 '12, 9:02 a.m.

Confirmation Cancel Confirm