Vulnerability Bulletins

IBM Security Bulletin: A Security Vulnerability exists in the Dojo runtime that affects Rational Application Developer

   
Affected software IBM
 
The dojox/form/resources/fileuploader.swf, dojox/form/resources/uploader.swf, dojox/av/resources/audio.swf, and dojox/av/resources/video.swf files exhibit an cross-site scripting (XSS) vulnerability. Any web application using the IBM Dojo Toolkit and providing those files might be subject to this vulnerability. CVE(s): CVE-2014-8917 Affected product(s) and affected version(s): Dojo 1.4 and 1.5 packaged with Rational Application Developer 8.0 and 8.5 Refer to the following reference

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_a_security_vulnerability_exists_in_the_dojo_runtime_that_affects_rational_application_developer?lang=en_us