CVE-2021-20351: XSS
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194708.
Other sources
IBM Engineering Requirements Quality Assistant is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-20351?
CVE-2021-20351 is a cross-site scripting vulnerability in IBM Engineering products that allows users to embed arbitrary JavaScript code in the Web UI.
Which IBM products are affected by CVE-2021-20351?
IBM RDNG 6.0.2, IBM DOORS Next 7.0, IBM DOORS Next 7.0.1, IBM DOORS Next 7.0.2, IBM RDNG 6.0.6.1, IBM RDNG 6.0.6, IBM Pub 7.0.1, IBM Pub 7.0.2, IBM Pub 7.0, IBM EWM 7.0.2, IBM EWM 7.0.1, IBM RTC 6.0.2, IBM RTC 6.0.6.1, IBM EWM 7.0, IBM RTC 6.0.6, IBM Global Configuration Management, IBM ETM 7.0.2, IBM RQM 6.0.6.1, IBM ETM 7.0.1, IBM RQM 6.0.6, IBM ETM 7.0.0, IBM RQM 6.0.2, and IBM Engineering Requirements Quality Assistant On-Premises.
What is the severity of CVE-2021-20351?
CVE-2021-20351 has a severity rating of 5.4 (medium).
How does CVE-2021-20351 impact the affected systems?
CVE-2021-20351 allows attackers to embed arbitrary JavaScript code in the Web UI of IBM Engineering products, potentially leading to credentials disclosure within a trusted session.
Is there a fix available for CVE-2021-20351?
IBM has provided fixes for the affected products. Please refer to the IBM support page for specific instructions.