CVE-2020-4856: XSS
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190459.
Other sources
IBM Engineering Requirements Management DOORS Next is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2020-4856.
What products are affected by this vulnerability?
IBM Engineering Requirements Management DOORS Next (RDNG) versions up to 6.0.2 and DOORS Next versions up to 7.0.2 are affected.
What is the severity of CVE-2020-4856?
The severity of this vulnerability is medium with a CVSS score of 6.4.
How does the vulnerability affect the system?
This vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
Are there any references available for this vulnerability?
Yes, you can find more information and references at the following links: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/190459) and [Link 2](https://www.ibm.com/support/pages/node/6417585).