CVE-2021-20338: XSS
IBM Engineering Test Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194449.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-20338.
What is the severity of CVE-2021-20338?
The severity of CVE-2021-20338 is medium, with a severity value of 5.4.
Which products are affected by CVE-2021-20338?
The following IBM products are affected by CVE-2021-20338: IBM DOORS Next, IBM RDNG, IBM Pub, IBM RQM, IBM ETM, IBM CLM, IBM ELM, IBM RMM, IBM RELM, IBM ENI, IBM Rational DOORS Next Generation, IBM Rational Engineering Lifecycle Manager, IBM Rational Quality Manager, and IBM RDNG.
What is the impact of CVE-2021-20338?
CVE-2021-20338 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
Are there any fix or mitigation steps for CVE-2021-20338?
Yes, IBM has provided a fix for CVE-2021-20338. Please refer to the IBM support page for more information.