CVE-2020-4866: XSS
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190742.
Other sources
IBM Engineering Workflow Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4866?
The severity of CVE-2020-4866 is medium with a CVSS score of 5.4.
How does CVE-2020-4866 affect IBM Engineering Workflow Management?
CVE-2020-4866 allows for cross-site scripting in IBM Engineering Workflow Management, potentially leading to credentials disclosure within a trusted session.
Which versions of IBM products are affected by CVE-2020-4866?
IBM RDNG 6.0.2, IBM DOORS Next 7.0, IBM DOORS Next 7.0.1, IBM DOORS Next 7.0.2, IBM RDNG 6.0.6.1, IBM RDNG 6.0.6, IBM Pub 7.0.1, IBM Pub 7.0.2, IBM Pub 7.0, IBM EWM 7.0.2, IBM EWM 7.0.1, IBM RTC 6.0.2, IBM RTC 6.0.6.1, IBM EWM 7.0, IBM RTC 6.0.6, IBM Global Configuration Management, IBM ETM 7.0.2, IBM RQM 6.0.6.1, IBM ETM 7.0.1, IBM RQM 6.0.6, IBM ETM 7.0.0, IBM RQM 6.0.2, and IBM Engineering Requirements Quality Assistant On-Premises are affected by CVE-2020-4866.
How do I fix CVE-2020-4866 in IBM Engineering Workflow Management?
To fix CVE-2020-4866 in IBM Engineering Workflow Management, update to the latest version of the affected product.
What is cross-site scripting?
Cross-site scripting (XSS) is a vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.