CVE-2020-4295: XSS
IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176408.
Other sources
IBM DOORS Next Generation (DNG/RRC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is IBM DOORS Next Generation (DNG/RRC) vulnerability CVE-2020-4295?
IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
How does the vulnerability CVE-2020-4295 impact IBM DOORS Next Generation (DNG/RRC)?
The vulnerability allows an attacker to embed malicious JavaScript code in the Web UI, which can alter the intended functionality of the application and potentially result in credentials disclosure.
What is the severity level of vulnerability CVE-2020-4295?
The severity level of vulnerability CVE-2020-4295 is medium, with a CVSS score of 5.4.
Which versions of IBM DOORS Next Generation (DNG/RRC) are affected by vulnerability CVE-2020-4295?
Versions 6.0.2, 6.0.6, 6.0.6.1, and 7.0 of IBM DOORS Next Generation (DNG/RRC) are affected by vulnerability CVE-2020-4295.
How can the vulnerability CVE-2020-4295 be mitigated?
To mitigate the vulnerability CVE-2020-4295, IBM recommends applying the necessary fix packs or upgrading to a fixed version. Please refer to the IBM support page for detailed instructions and patches.