First published: Mon Mar 04 2019(Updated: )
IBM DOORS Next Generation (DNG/RRC) 6.0.2 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152736.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational DOORS Next Generation | >=6.0.2<=6.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1912 is classified as a high severity vulnerability due to its potential for credential disclosure through cross-site scripting.
To fix CVE-2018-1912, you should upgrade IBM DOORS Next Generation to version 6.0.7 or later where the vulnerability is addressed.
CVE-2018-1912 affects IBM Rational DOORS Next Generation versions 6.0.2 through 6.0.6.
The impact of CVE-2018-1912 can lead to unauthorized disclosure of credentials within a trusted session due to the embedding of malicious JavaScript.
Currently, the recommended approach is to apply the upgrade rather than relying on a workaround for CVE-2018-1912.