Learn about CVE-2017-1338 affecting IBM DOORS Next Generation versions 4.0, 5.0, and 6.0. Understand the risks of cross-site scripting and how to mitigate this vulnerability.
Cross-site scripting vulnerabilities have been identified in versions 4.0, 5.0, and 6.0 of IBM DOORS Next Generation (DNG/RRC). These vulnerabilities allow users to inject JavaScript code into the Web UI, posing a risk of exposing credentials during a trusted session.
Understanding CVE-2017-1338
What is CVE-2017-1338?
IBM DOORS Next Generation (DNG/RRC) versions 4.0, 5.0, and 6.0 are susceptible to cross-site scripting, enabling unauthorized JavaScript injection in the Web UI.
The Impact of CVE-2017-1338
This vulnerability could lead to the alteration of functionality, potentially exposing credentials during trusted sessions.
Technical Details of CVE-2017-1338
Vulnerability Description
Users can embed arbitrary JavaScript code in the Web UI, affecting the intended functionality and risking credential disclosure.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates