Stored Cross-Site Scripting Vulnerability in IBM Engineering Products
CVE-2020-4863
6.4MEDIUM
Key Information:
- Vendor
IBM
- Status
- Vendor
- CVE Published:
- 4 March 2021
What is CVE-2020-4863?
IBM Engineering products are affected by a stored cross-site scripting vulnerability that enables users to inject arbitrary JavaScript code into the Web UI. This could potentially alter normal functionality and lead to the disclosure of sensitive credentials within a trusted user session, exposing organizations to significant security risks. For detailed information, you can refer to the IBM support page and the X-Force vulnerability database.
Affected Version(s)
Engineering Lifecycle Optimization 7.0
Engineering Lifecycle Optimization 7.0.1
Engineering Lifecycle Optimization 7.0.2