Use of Web Link to Untrusted Target with window.opener Access in Engineering Lifecycle Optimization - Engineering Insights - CVE-2024-39727
Published: December 30, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to application uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.
Affected software
Jazz Reporting Service
IBM Engineering Requirements Management DOORS Next
IBM Engineering Lifecycle Optimization - Publishing
How to mitigate CVE-2024-39727
Jazz Reporting Service - addressed in versions 7.0.2 iFix033, 7.0.3 iFix0012
IBM Engineering Requirements Management DOORS Next - addressed in versions 7.0.2 ifix 33, 7.0.3 ifix 13, 7.1.0 ifix 02
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.2.32, 7.0.3.10
External References
Related Security Bulletins
- Use of Web Link to Untrusted Target with window.opener Access in IBM Engineering Lifecycle Optimization - Engineering Insights
- Use of Web Link to Untrusted Target with window.opener Access in IBM Engineering Lifecycle Optimization - Engineering Publishing
- IBM Jazz Reporting Service update for IBM Engineering Lifecycle Optimization - Engineering Insights
- IBM Engineering Requirements Management DOORS Next update for IBM Engineering Lifecycle Optimization - Engineering Insights