First published: Mon Jul 27 2020(Updated: )
IBM Engineering Requirements Management DOORS Next Generation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Engineering Requirements Management DOORS Next | =7.0 | |
<=6.0.6.1 | ||
<=6.0.6 | ||
<=7.0.0 | ||
<=6.0.2 | ||
<=7.0 | ||
<=6.0.6.1 | ||
<=6.0.6 | ||
<=7.0 | ||
<=6.0.2 | ||
<=6.0.2 | ||
<=6.0.6.1 | ||
<=6.0.6 | ||
<=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-4542.
The severity level of CVE-2020-4542 is medium with a CVSS score of 5.4.
The affected IBM products include RQM, ETM, EWM, CLM, ELM, RDNG, and Engineering Requirements Management DOORS Next.
CVE-2020-4542 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
You can find more information about CVE-2020-4542 on the IBM X-Force Exchange website and the IBM support page.