Cross-Site Scripting Vulnerability in IBM Jazz Foundation Products
CVE-2020-4524
5.4MEDIUM
Key Information:
- Vendor
- IBM
- Status
- Vendor
- CVE Published:
- 27 January 2021
Summary
IBM Jazz Foundation products are susceptible to cross-site scripting attacks, which can be exploited by embedding arbitrary JavaScript code into the application's web interface. This manipulation can compromise the intended functionality of the application and potentially lead to the unauthorized disclosure of user credentials within a trusted session. It is crucial for users and administrators of the affected IBM products to apply necessary patches and implement security measures to mitigate this risk.
Affected Version(s)
Engineering Lifecycle Optimization 7.0
Engineering Test Management 7.0.0
Engineering Workflow Management 7.0
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved