The vendor explicitly identifies these products as affected by this CVE.
- Polarion V2404
- Polarion V2410
- Summary
- The affected application allows arbitrary JavaScript code be included in document titles. This could allow an authenticated remote attacker to conduct a stored cross-site scripting attack by creating specially crafted document titles that are later viewed by other users of the application.
- Remediation
- Update to V2404.5 or later version
