First published: Wed Jun 27 2018(Updated: )
IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141415.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational DOORS Next Generation | =6.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1507 is classified with a medium severity due to its potential to leak sensitive information through cross-site scripting.
To fix CVE-2018-1507, upgrade IBM DOORS Next Generation to a version that addresses the vulnerability.
The implications of CVE-2018-1507 involve the risk of credential disclosure within trusted sessions due to the ability to embed malicious JavaScript.
CVE-2018-1507 affects users of IBM Rational DOORS Next Generation version 6.0.5.
Yes, CVE-2018-1507 can be exploited remotely since it targets the Web UI of the application.