Cross-Site Scripting Vulnerability in IBM Rational Focal Point
CVE-2014-0843 
Currently unrated
What is CVE-2014-0843?
A cross-site scripting (XSS) vulnerability exists within IBM Rational Focal Point versions 6.4.x, 6.5.x prior to 6.5.2.3, and 6.6.x prior to 6.6.1. This flaw allows remote authenticated users to execute arbitrary web scripts or HTML through the upload of malicious files. As a result, attackers can compromise the security of the application and potentially manipulate user sessions or steal sensitive information.