First published: Thu Feb 13 2020(Updated: )
IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172808.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DOORS Next Generation | =6.0.2 | |
IBM DOORS Next Generation | =6.0.6 | |
IBM DOORS Next Generation | =6.0.6.1 | |
IBM Rational DOORS Next Generation | =6.0.2 | |
IBM Rational DOORS Next Generation | =6.0.6 | |
IBM Rational DOORS Next Generation | =6.0.6.1 | |
<=6.0.2 | ||
<=6.0.6 | ||
<=6.0.6.1 | ||
<=6.0.6.1 | ||
<=6.0.6 | ||
<=6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4740 is a vulnerability in IBM DOORS Next Generation (DNG/RRC) that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
IBM DOORS Next Generation versions 6.0.2, 6.0.6, and 6.0.6.1 are affected by CVE-2019-4740.
The severity of CVE-2019-4740 is medium with a CVSS score of 5.4.
This vulnerability can be exploited by embedding arbitrary JavaScript code in the Web UI of IBM DOORS Next Generation, potentially leading to credentials disclosure.
Yes, IBM has released fixes for the affected versions of IBM DOORS Next Generation. It is recommended to update to the latest version to mitigate this vulnerability.