CVE-2020-4977: XSS
IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-4977.
What is the severity of CVE-2020-4977?
The severity of CVE-2020-4977 is medium.
How does CVE-2020-4977 affect IBM Engineering Lifecycle Optimization - Publishing?
CVE-2020-4977 allows users to embed arbitrary JavaScript code in the Web UI of IBM Engineering Lifecycle Optimization - Publishing, potentially leading to credentials disclosure.
What is the affected software for CVE-2020-4977?
The affected software for CVE-2020-4977 includes IBM Collaborative Lifecycle Management, IBM Engineering Lifecycle Management, IBM Engineering Lifecycle Optimization - Engineering Insights, IBM Engineering Lifecycle Optimization - Publishing, IBM Engineering Test Management, IBM Rational DOORS Next Generation, IBM Rational Engineering Lifecycle Manager, IBM Rational Quality Manager, and IBM RDNG.
How do I fix CVE-2020-4977?
To fix CVE-2020-4977, it is recommended to apply the necessary security patches provided by IBM.