IBM Engineering Lifecycle Optimization - Publishing Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting vulnerability has been identified in IBM Engineering Lifecycle Optimization - Publishing versions 7.0.2 and 7.0.3. The issue arises from a lack of validation for URIs, which could allow for the injection of malicious scripts.

Impact

Exploitation of this vulnerability could lead to cross-site scripting, allowing attackers to inject malicious scripts that could be executed in the context of the user's browser.

Remediation

Users can upgrade to IBM Engineering Lifecycle Optimization - Publishing version 7.0.3 (iFix016) or version 7.0.2 (iFix035).

Added: Aug 5, 2025, 2:19 PM
Updated: Aug 5, 2025, 2:39 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
1.7
exploitability
6.0
remediation
7.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.