First published: Tue Jan 26 2021(Updated: )
IBM Jazz Foundation could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Collaborative Lifecycle Management | =6.0.2 | |
Ibm Collaborative Lifecycle Management | =6.0.6 | |
Ibm Collaborative Lifecycle Management | =6.0.6.1 | |
IBM ENI | =7.0 | |
IBM Engineering Lifecycle Management | =7.0 | |
IBM Engineering Requirements Management DOORS Next | =6.0.2 | |
IBM Engineering Requirements Management DOORS Next | =6.0.6 | |
IBM Engineering Requirements Management DOORS Next | =6.0.6.1 | |
IBM Engineering Requirements Management DOORS Next | =7.0 | |
IBM Engineering Test Management | =7.0.0 | |
IBM Engineering Workflow Management | =6.0.2 | |
IBM Engineering Workflow Management | =6.0.6 | |
IBM Engineering Workflow Management | =6.0.6.1 | |
IBM Engineering Workflow Management | =7.0 | |
IBM Engineering Workflow Management | =7.0.2 | |
IBM Global Configuration Management | ||
IBM Rational Engineering Lifecycle Manager | =6.0.2 | |
IBM Rational Engineering Lifecycle Manager | =6.0.6 | |
IBM Rational Engineering Lifecycle Manager | =6.0.6.1 | |
IBM Rational Quality Manager | =6.0.2 | |
IBM Rational Quality Manager | =6.0.6 | |
IBM Rational Quality Manager | =6.0.6.1 | |
Ibm Rhapsody Design Manager | =6.0.2 | |
Ibm Rhapsody Design Manager | =6.0.6 | |
Ibm Rhapsody Design Manager | =6.0.6.1 | |
Ibm Rhapsody Design Manager | =7.0 | |
IBM Rhapsody Model Manager | =6.0.2 | |
IBM Rhapsody Model Manager | =6.0.6 | |
IBM Rhapsody Model Manager | =6.0.6.1 | |
IBM Rhapsody Model Manager | =7.0 | |
<=7.0.2 | ||
<=6.0.2 | ||
<=6.0.6.1 | ||
<=7.0 | ||
<=6.0.6 | ||
<=6.0.2 | ||
<=7.0 | ||
<=6.0.6.1 | ||
<=6.0.6 | ||
<=6.0.6 | ||
<=6.0.6.1 | ||
<=6.0.2 | ||
<=7.0 | ||
<=6.0.6.1 | ||
<=6.0.6 | ||
<=7.0 | ||
<=6.0.2 | ||
<=6.0.6.1 | ||
<=6.0.6 | ||
<=7.0 | ||
<=6.0.2 | ||
<=6.0.6.1 | ||
<=6.0.6 | ||
<=7.0.0 | ||
<=6.0.2 | ||
<=6.0.6.1 | ||
<=6.0.6 | ||
<=7.0 | ||
<=6.0.2 | ||
<=All |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4547 is medium with a CVSS score of 5.4.
A remote attacker can exploit CVE-2020-4547 by persuading a victim to visit a malicious website and hijack their click actions.
IBM Jazz Foundation products, including IBM EWM, IBM RTC, IBM RDNG, IBM Rhapsody DM, IBM RMM, IBM CLM, IBM ELM, IBM RQM, IBM ETM, IBM RELM, IBM ENI, IBM Global Configuration Management, IBM Rational Engineering Lifecycle Manager, IBM Rational Quality Manager, IBM Rhapsody Design Manager, IBM Rhapsody Model Manager, are affected by CVE-2020-4547.
It is recommended to apply the necessary security updates provided by IBM to mitigate the vulnerability.
You can find more information about CVE-2020-4547 on the IBM X-Force Exchange website and the IBM Support pages.