Description
IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192470.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-26224 | IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192470. |
References
History
No history.
Subscriptions
Ibm
Subscribe
Collaborative Lifecycle Management
Subscribe
Engineering Lifecycle Management
Subscribe
Engineering Lifecycle Optimization - Engineering Insights
Subscribe
Engineering Lifecycle Optimization - Publishing
Subscribe
Engineering Test Management
Subscribe
Rational Doors Next Generation
Subscribe
Rational Engineering Lifecycle Manager
Subscribe
Rational Quality Manager
Subscribe
Removable Media Manager
Subscribe
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-09-16T20:47:42.592Z
Reserved: 2019-12-30T00:00:00.000Z
Link: CVE-2020-4977
No data.
Status : Modified
Published: 2021-06-02T21:15:07.400
Modified: 2024-11-21T05:33:30.077
Link: CVE-2020-4977
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD