CVE-2017-1607Cross-site Scripting in IBM Rational Doors Next Generation

Severity
5.4MEDIUMNVD
GHSA7.5CISA7.8
EPSS
0.3%
top 49.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 27
Latest updateMay 17

Description

IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132927.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

Patches

🔴Vulnerability Details

9
GHSA
GHSA-f27m-v696-mmmq: IBM DOORS Next Generation (DNG/RRC) 62022-05-17
GHSA
ChakraCore vulnerable to remote code execution due to insufficient InlineCache check2022-05-17
GHSA
ChakraCore vulnerable to privilege escalation due to exposure from scriptFunction2022-05-14
GHSA
ChakraCore vulnerable to remote code execution2022-05-14
GHSA
ChakraCore RCE Vulnerability2022-05-14

💥Exploits & PoCs

3
Exploit-DB
Microsoft Windows - 'nt!NtQueryInformationJobObject (information class 28)' Kernel Stack Memory Disclosure2017-06-22
Exploit-DB
Microsoft Windows - 'nt!NtQueryInformationJobObject (information class 12)' Kernel Stack Memory Disclosure2017-06-22
Exploit-DB
Microsoft Windows Kernel - 'win32kfull!SfnINLPUAHDRAWMENUITEM' Stack Memory Disclosure2017-04-13

📋Vendor Advisories

2
CISA
Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability2022-03-03
CISA
Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability2022-03-03
CVE-2017-1607 — Cross-site Scripting in IBM | cvebase