CVE-2020-4855: XSS
IBM Engineering Requirements Management DOORS Next is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190457.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-4855?
CVE-2020-4855 is a vulnerability in IBM Engineering Requirements Management DOORS Next that allows users to embed arbitrary JavaScript code in the Web UI.
How does CVE-2020-4855 affect IBM Jazz Foundation products?
CVE-2020-4855 allows for cross-site scripting, potentially leading to credentials disclosure within a trusted session.
Which products are affected by CVE-2020-4855?
IBM EWM, IBM RTC, IBM RDNG, IBM DOORS Next, IBM Rhapsody DM, IBM RDM, IBM RMM, IBM CLM, IBM ELM, IBM RQM, and IBM ENI are among the products affected by CVE-2020-4855.
What is the severity of CVE-2020-4855?
CVE-2020-4855 has a severity rating of medium with a CVSS score of 5.4.
How can I fix CVE-2020-4855?
To fix CVE-2020-4855, it is recommended to apply the latest security patches provided by IBM.