CVE-2020-4524: XSS
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182434.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-4524.
What is the severity of CVE-2020-4524?
The severity of CVE-2020-4524 is medium with a severity value of 5.4.
Which products are affected by CVE-2020-4524?
IBM Jazz Foundation products like EWM, RTC, RDNG, Rhapsody DM, RDM, RMM, CLM, ELM, RQM, ENI, Global Configuration Management, RELM, and Engineering Workflow Management, are affected by CVE-2020-4524.
What is the risk of CVE-2020-4524?
CVE-2020-4524 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
Is there a fix available for CVE-2020-4524?
Yes, IBM has provided a fix for CVE-2020-4524. Please refer to the IBM support page for more information.