← back
CVE-2025-1826

IBM Jazz Foundation cross-site scripting

CVSS 5.4 MEDIUMEPSS 0.2%CWE-79
IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034, 7.0.3 to 7.0.3 iFix016, and 7.1.0 to 7.1.0 iFix004) is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users on the host network to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected products
IBM · Jazz Foundation

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →