CVE-2025-1826

⚪ Do wiadomości

Wstrzyknięcie skryptów w IBM DOORS Next umożliwia ujawnienie danych uwierzytelniających.

CVSS
5.4
EPSS
0.2%
Exploit
none
Vendor
ibm
Opis źródłowy (NVD)

IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034, 7.0.3 to 7.0.3 iFix016, and 7.1.0 to 7.1.0 iFix004) is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users on the host network to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.4
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2025-10-07 18:15:58 UTC
Ostatnia modyfikacja (NVD)2026-10-08 22:10:00 UTC
Referencje