IBM / Engineering Lifecycle Optimization - Publishing
28 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-45191 | IBM Engineering Lifecycle Optimization information disclosure | HIGH | 7.5 | Feb 9, 2024 |
| CVE-2023-45190 | IBM Engineering Lifecycle Optimization HTTP header injection | MEDIUM | 6.1 | Feb 9, 2024 |
| CVE-2023-45187 | IBM Engineering Lifecycle Optimization - Publishing session fixation | HIGH | 8.8 | Feb 9, 2024 |
| CVE-2021-39028 | IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header injection, caused by improper validation… | MEDIUM | 5.4 | Jul 14, 2022 |
| CVE-2021-39019 | IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitive information through an HTTP GET reque… | MEDIUM | 6.5 | Jul 14, 2022 |
| CVE-2021-39018 | IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose sensitive information in a SQL error message that coul… | MEDIUM | 4.3 | Jul 14, 2022 |
| CVE-2021-39017 | IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to upload arbitrary files, caused by im… | MEDIUM | 6.5 | Jul 14, 2022 |
| CVE-2021-39016 | IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 does not sufficiently monitor or control transmitted network traffic… | MEDIUM | 4.3 | Jul 14, 2022 |
| CVE-2021-39015 | IBM Engineering Lifecycle Optimization - Publishing 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit… | MEDIUM | 5.4 | Jul 14, 2022 |
| CVE-2021-29670 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-29668 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20371 | IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser… | MEDIUM | 6.5 | Jun 2, 2021 |
| CVE-2021-20348 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20347 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20346 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20345 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20343 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20338 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2020-5030 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2020-4977 | IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2020-4732 | IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-… | MEDIUM | 6.5 | Jun 2, 2021 |
| CVE-2020-4495 | IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a… | HIGH | 8.8 | Jun 2, 2021 |
| CVE-2020-4316 | IBM Publishing Engine 6.0.6, 6.0.6.1, and 7.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the co… | MEDIUM | 4.7 | Jul 16, 2020 |
| CVE-2019-4431 | IBM Rational Publishing Engine 6.0.6 and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t… | MEDIUM | 5.4 | Feb 12, 2020 |
| CVE-2018-1951 | IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the… | MEDIUM | 5.4 | Jan 4, 2019 |
Showing 1 to 25 of 28 CVEs