CVE-2020-4542: XSS
IBM Engineering Requirements Management DOORS Next Generation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 183046.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-4542.
What is the severity level of CVE-2020-4542?
The severity level of CVE-2020-4542 is medium with a CVSS score of 5.4.
Which IBM products are affected by CVE-2020-4542?
The affected IBM products include RQM, ETM, EWM, CLM, ELM, RDNG, and Engineering Requirements Management DOORS Next.
How does CVE-2020-4542 affect users?
CVE-2020-4542 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
How can I obtain more information about CVE-2020-4542?
You can find more information about CVE-2020-4542 on the IBM X-Force Exchange website and the IBM support page.