Engineering Lifecycle Optimization - Engineering Insights
IBM · 18 CVEs
IBM Engineering Lifecycle Optimization - Engineering Insights tabnabbing
Dec 25, 2024
IBM Engineering Lifecycle Optimization - Engineering Insights information disclosure
Dec 25, 2024
IBM Engineering Insights XML external entity injection
Nov 15, 2024
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…
Jul 28, 2021
IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated atta…
Jul 28, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows user…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows user…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow a…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow a…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow a…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow a…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow a…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows user…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows user…
Jun 2, 2021
IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability al…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due…
Jun 2, 2021
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused…
Jun 2, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-39727 | IBM Engineering Lifecycle Optimization - Engineering Insights tabnabbing | CRITICAL | 0.34% | Dec 25, 2024 |
| CVE-2024-39725 | IBM Engineering Lifecycle Optimization - Engineering Insights information disclosure | MEDIUM | 0.38% | Dec 25, 2024 |
| CVE-2024-39726 | IBM Engineering Insights XML external entity injection | HIGH | 0.70% | Nov 15, 2024 |
| CVE-2020-5004 | IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte… | MEDIUM | 0.50% | Jul 28, 2021 |
| CVE-2020-4974 | IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from… | MEDIUM | 0.60% | Jul 28, 2021 |
| CVE-2021-29670 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2021-29668 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2021-20371 | IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser… | MEDIUM | 1.20% | Jun 2, 2021 |
| CVE-2021-20348 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2021-20347 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2021-20346 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2021-20345 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2021-20343 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2021-20338 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2020-5030 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2020-4977 | IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript… | MEDIUM | 0.50% | Jun 2, 2021 |
| CVE-2020-4732 | IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-… | MEDIUM | 0.80% | Jun 2, 2021 |
| CVE-2020-4495 | IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a… | HIGH | 2.65% | Jun 2, 2021 |
Showing 1 to 18 of 18 CVEs