CVE-2019-4740: XSS
IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172808.
Other sources
IBM DOORS Next Generation (DNG/RRC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-4740?
CVE-2019-4740 is a vulnerability in IBM DOORS Next Generation (DNG/RRC) that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
Which versions of IBM DOORS Next Generation are affected by CVE-2019-4740?
IBM DOORS Next Generation versions 6.0.2, 6.0.6, and 6.0.6.1 are affected by CVE-2019-4740.
What is the severity of CVE-2019-4740?
The severity of CVE-2019-4740 is medium with a CVSS score of 5.4.
How can this cross-site scripting vulnerability be exploited?
This vulnerability can be exploited by embedding arbitrary JavaScript code in the Web UI of IBM DOORS Next Generation, potentially leading to credentials disclosure.
Is there a fix available for CVE-2019-4740?
Yes, IBM has released fixes for the affected versions of IBM DOORS Next Generation. It is recommended to update to the latest version to mitigate this vulnerability.