Collaborative Lifecycle Management
IBM · 29 CVEs
IBM Jazz Foundation information disclosure
Oct 6, 2023
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows user…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows user…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow a…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow a…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow a…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow a…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow a…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows user…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows user…
Jun 2, 2021
IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability al…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused…
Jun 2, 2021
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar…
Apr 12, 2021
IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt…
Apr 12, 2021
IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a…
Apr 12, 2021
IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed a…
Apr 12, 2021
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…
Jan 27, 2021
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…
Jan 27, 2021
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…
Jan 27, 2021
IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a…
Jan 27, 2021
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…
Jan 27, 2021
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…
Jan 8, 2021
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…
Jan 8, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2022-34355 | IBM Jazz Foundation information disclosure | MEDIUM | 0.19% | Oct 6, 2023 |
| CVE-2021-29670 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2021-29668 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2021-20371 | IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser… | MEDIUM | 1.20% | Jun 2, 2021 |
| CVE-2021-20348 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2021-20347 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2021-20346 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2021-20345 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2021-20343 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2021-20338 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2020-5030 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2020-4977 | IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2020-4732 | IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-… | MEDIUM | 0.80% | Jun 2, 2021 |
| CVE-2020-4495 | IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a… | HIGH | 2.65% | Jun 2, 2021 |
| CVE-2021-20519 | IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt… | MEDIUM | 0.62% | Apr 12, 2021 |
| CVE-2020-4965 | IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-For… | HIGH | 0.72% | Apr 12, 2021 |
| CVE-2020-4964 | IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application wh… | MEDIUM | 0.64% | Apr 12, 2021 |
| CVE-2020-4920 | IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t… | MEDIUM | 0.62% | Apr 12, 2021 |
| CVE-2021-20357 | IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alter… | MEDIUM | 0.66% | Jan 27, 2021 |
| CVE-2020-4865 | IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alter… | MEDIUM | 0.66% | Jan 27, 2021 |
| CVE-2020-4855 | IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alter… | MEDIUM | 0.66% | Jan 27, 2021 |
| CVE-2020-4547 | IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a… | MEDIUM | 0.82% | Jan 27, 2021 |
| CVE-2020-4524 | IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alter… | MEDIUM | 0.66% | Jan 27, 2021 |
| CVE-2020-4733 | IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte… | MEDIUM | 0.56% | Jan 8, 2021 |
| CVE-2020-4697 | IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte… | MEDIUM | 0.56% | Jan 8, 2021 |
Showing 1 to 25 of 29 CVEs