IBM Support

PK83866: REQWEB IS VULNERABLE TO CROSS-SITE SCRIPTING

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • ReqWeb is vulnerable to Cross-Site Scripting attacks.  The follo
    wing links demonstrate the problem.
    
    http://localhost/ReqWeb/Doc_Frame.jsp?--??/script??script?alert(
    37186)?/script?
    
    http://localhost:9080/ReqWeb7/ProjInfo_Page.jsp??PackageID=187';
    alert(3445);//?viz=1236358927875
    
    http://localhost:9080/ReqWeb7/Doc_Frame.jsp?DocAction=21'+alert(
    3200)+'?DocKey=null
    
    The above examples result in an Alert box appearing which shows
    the script can be run against ReqWeb.  This allows for potential
     attacks against the site.  These types of attacks should be blo
    cked to prevent attacks of this type.
    

Local fix

Problem summary

Problem conclusion

  • The code has been modified to process script like the
    example provided and prevent it from being executed.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PK83866

  • Reported component name

    REQUISITEPRO WI

  • Reported component ID

    5724G3900

  • Reported release

    710

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2009-04-01

  • Closed date

    2009-10-15

  • Last modified date

    2009-10-15

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    REQUISITEPRO WI

  • Fixed component ID

    5724G3900

Applicable component levels

  • R710 PSN

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSSHCT","label":"Rational RequisitePro"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.1","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
24 October 2021