CVE-2020-4396: XSS
IBM Engineering Test Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 179359.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-4396.
What is the severity rating for CVE-2020-4396?
The severity rating for CVE-2020-4396 is medium.
Which products are affected by CVE-2020-4396?
IBM RQM versions 6.0.6.1 and 6.0.6, IBM ETM version 7.0.0, IBM EWM version 7.0, IBM CLM versions 6.0.6.1 and 6.0.6, IBM ELM version 7.0, IBM RDNG versions 6.0.2, 6.0.6.1, and 6.0.6, and IBM DOORS Next version 7.0 are affected by CVE-2020-4396.
What is the impact of CVE-2020-4396?
CVE-2020-4396 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
How can I fix CVE-2020-4396?
Apply the necessary security patch provided by IBM to fix CVE-2020-4396.