First published: Wed Mar 06 2019(Updated: )
IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152735.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational DOORS | >=5.0.0<=5.0.2 | |
IBM Rational DOORS | >=6.0.0<=6.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1911 is classified as a medium-severity cross-site scripting (XSS) vulnerability.
To fix CVE-2018-1911, upgrade your IBM DOORS Next Generation software to version 5.0.3 or 6.0.7 or later.
CVE-2018-1911 affects IBM DOORS Next Generation versions 5.0 through 5.0.2 and 6.0 through 6.0.6.
Exploiting CVE-2018-1911 allows attackers to embed arbitrary JavaScript code in the Web UI, potentially leading to credential disclosure.
Users of IBM DOORS Next Generation within an organization are at risk of this vulnerability.