CVE-2020-4691: XSS
IBM Engineering Workflow Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186698.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4691?
The severity of CVE-2020-4691 is medium.
What is the impact of CVE-2020-4691?
CVE-2020-4691 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
Which versions of IBM Engineering Workflow Management are affected by CVE-2020-4691?
IBM Engineering Workflow Management versions 7.0 and 7.0.1 are affected by CVE-2020-4691.
What is cross-site scripting (XSS)?
Cross-site scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
How can I fix CVE-2020-4691?
Apply the necessary patches or updates provided by IBM to fix CVE-2020-4691.