First published: Mon May 31 2021(Updated: )
IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Collaborative Lifecycle Management | =6.0.6 | |
Ibm Collaborative Lifecycle Management | =6.0.6.1 | |
IBM Engineering Lifecycle Management | =7.0 | |
IBM Engineering Lifecycle Management | =7.0.1 | |
IBM Engineering Lifecycle Management | =7.0.2 | |
IBM Engineering Lifecycle Optimization - Engineering Insights | =7.0 | |
IBM Engineering Lifecycle Optimization - Engineering Insights | =7.0.1 | |
IBM Engineering Lifecycle Optimization - Engineering Insights | =7.0.2 | |
IBM Engineering Lifecycle Optimization - Publishing | =7.0 | |
IBM Engineering Lifecycle Optimization - Publishing | =7.0.1 | |
IBM Engineering Lifecycle Optimization - Publishing | =7.0.2 | |
IBM Engineering Test Management | =7.0.0 | |
IBM Engineering Test Management | =7.0.1 | |
IBM Rational DOORS Next Generation | =6.0.6 | |
IBM Rational DOORS Next Generation | =6.0.6.1 | |
IBM Rational DOORS Next Generation | =7.0 | |
IBM Rational DOORS Next Generation | =7.0.1 | |
IBM Rational DOORS Next Generation | =7.0.2 | |
IBM Rational Engineering Lifecycle Manager | =6.0.6 | |
IBM Rational Engineering Lifecycle Manager | =6.0.6.1 | |
IBM Rational Quality Manager | =6.0.6 | |
IBM Rational Quality Manager | =6.0.6.1 | |
Ibm Removable Media Manager | =6.0.6 | |
Ibm Removable Media Manager | =6.0.6.1 | |
Ibm Removable Media Manager | =7.0 | |
IBM DOORS Next | <=7.0.2 | |
IBM DOORS Next | <=7.0 | |
IBM DOORS Next | <=7.0.1 | |
IBM RDNG | <=6.0.6.1 | |
IBM RDNG | <=6.0.6 | |
IBM Pub | <=7.0.1 | |
IBM Pub | <=7.0.2 | |
IBM Pub | <=7.0 | |
IBM RQM | <=6.0.6.1 | |
IBM ETM | <=7.0.1 | |
IBM RQM | <=6.0.6 | |
IBM ETM | <=7.0.0 | |
IBM CLM | <=6.0.6.1 | |
IBM CLM | <=6.0.6 | |
IBM ELM | <=7.0.2 | |
IBM ELM | <=7.0 | |
IBM ELM | <=7.0.1 | |
IBM RMM | <=6.0.6.1 | |
IBM RMM | <=6.0.6 | |
IBM RMM | <=7.0 | |
IBM RELM | <=6.0.6.1 | |
IBM ENI | <=7.0.1 | |
IBM RELM | <=6.0.6 | |
IBM ENI | <=7.0 | |
IBM ENI | <=7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-4977.
The severity of CVE-2020-4977 is medium.
CVE-2020-4977 allows users to embed arbitrary JavaScript code in the Web UI of IBM Engineering Lifecycle Optimization - Publishing, potentially leading to credentials disclosure.
The affected software for CVE-2020-4977 includes IBM Collaborative Lifecycle Management, IBM Engineering Lifecycle Management, IBM Engineering Lifecycle Optimization - Engineering Insights, IBM Engineering Lifecycle Optimization - Publishing, IBM Engineering Test Management, IBM Rational DOORS Next Generation, IBM Rational Engineering Lifecycle Manager, IBM Rational Quality Manager, and IBM RDNG.
To fix CVE-2020-4977, it is recommended to apply the necessary security patches provided by IBM.