CVE-2019-4748: XSS
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173174.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-4748?
CVE-2019-4748 is a vulnerability in IBM Jazz Team Server-based Applications that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
How severe is CVE-2019-4748?
CVE-2019-4748 has a severity value of 5.4, which is considered medium.
Which IBM products are affected by CVE-2019-4748?
IBM ETM 7.0, IBM RQM 6.0.6.1, IBM RQM 6.0.6, IBM RQM 6.0.2, IBM DOORS Next 7.0, IBM RDNG 6.0.2, IBM RDNG 6.0.6.1, IBM RDNG 6.0.6, IBM EWM 7.0, IBM RTC 6.0.2, IBM RTC 6.0.6.1, IBM RTC 6.0.6, IBM ELM 7.0, IBM CLM 6.0.6.1, IBM CLM 6.0.6, IBM CLM 6.0.2, IBM RDM 7.0, IBM Rhapsody DM 6.0.6, and IBM Rhapsody DM 6.0.6.1 are affected by CVE-2019-4748.
How can I fix CVE-2019-4748 vulnerability?
To fix the CVE-2019-4748 vulnerability, IBM recommends applying the necessary patches and fixes provided by IBM.
Where can I find more information about CVE-2019-4748 vulnerability?
More information about the CVE-2019-4748 vulnerability can be found on the IBM X-Force ID: 173174 page and the IBM support website.