IBM / Engineering Test Management
45 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-43054 | IBM Engineering Test Management cross-site scripting | MEDIUM | 6.4 | Mar 3, 2024 |
| CVE-2021-38934 | IBM Engineering Test Management 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code… | MEDIUM | 5.4 | Aug 29, 2022 |
| CVE-2020-5004 | IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte… | MEDIUM | 5.4 | Jul 28, 2021 |
| CVE-2020-4974 | IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from… | MEDIUM | 6.3 | Jul 28, 2021 |
| CVE-2021-29670 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-29668 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20371 | IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser… | MEDIUM | 6.5 | Jun 2, 2021 |
| CVE-2021-20348 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20347 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20346 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20345 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20343 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20338 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2020-5030 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2020-4977 | IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2020-4732 | IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-… | MEDIUM | 6.5 | Jun 2, 2021 |
| CVE-2020-4495 | IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a… | HIGH | 8.8 | Jun 2, 2021 |
| CVE-2021-20519 | IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt… | MEDIUM | 5.4 | Apr 12, 2021 |
| CVE-2020-4965 | IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-For… | HIGH | 7.5 | Apr 12, 2021 |
| CVE-2020-4964 | IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application wh… | MEDIUM | 4.3 | Apr 12, 2021 |
| CVE-2020-4920 | IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t… | MEDIUM | 5.4 | Apr 12, 2021 |
| CVE-2021-20351 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering… | MEDIUM | 5.4 | Mar 4, 2021 |
| CVE-2021-20350 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering… | MEDIUM | 5.4 | Mar 4, 2021 |
| CVE-2021-20340 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering… | MEDIUM | 5.4 | Mar 4, 2021 |
| CVE-2020-4975 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering… | MEDIUM | 5.4 | Mar 4, 2021 |
Showing 1 to 25 of 45 CVEs