CVE-2020-4857: XSS
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190460.
Other sources
IBM Engineering Requirements Management DOORS Next is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-4857.
Which IBM Engineering products are affected by this vulnerability?
IBM Engineering products RDNG, DOORS Next, PUB, EWM, RTC, Global Configuration Management, ETM, RQM, and Engineering Requirements Quality Assistant On-Premises are affected by this vulnerability.
What is the severity of vulnerability CVE-2020-4857?
The severity of vulnerability CVE-2020-4857 is medium with a CVSS score of 6.4.
How does the vulnerability CVE-2020-4857 work?
The vulnerability CVE-2020-4857 allows users to embed arbitrary JavaScript code in the IBM Engineering Requirements Management DOORS Next Web UI, potentially leading to credentials disclosure within a trusted session.
Are there any fixes or patches available for vulnerability CVE-2020-4857?
Yes, IBM has provided fixes or patches for the affected IBM Engineering products to address vulnerability CVE-2020-4857. Please refer to the IBM support pages for more information.