CVE-2020-4546: XSS
IBM Engineering Workflow Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183314.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-4546?
IBM Engineering Workflow Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
What is the severity of CVE-2020-4546?
The severity of CVE-2020-4546 is medium, with a severity value of 5.4.
Which IBM products are affected by CVE-2020-4546?
IBM RDNG, IBM DOORS Next, IBM RTC, IBM EWM, IBM Engineering Requirements Management DOORS Next, IBM RELM, IBM ENI, IBM RQM, IBM ETM, IBM CLM, and IBM ELM are affected by CVE-2020-4546.
How can the vulnerability CVE-2020-4546 be fixed?
To mitigate the vulnerability, it is recommended to apply the necessary security fixes provided by IBM.
Where can I find more information about CVE-2020-4546?
You can find more information about CVE-2020-4546 on the IBM X-Force Exchange website and the IBM Support pages.