IBM / Rational Engineering Lifecycle Manager
141 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-29844 | IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from… | HIGH | 8.8 | Oct 27, 2021 |
| CVE-2021-29786 | IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172. | MEDIUM | 6.5 | Oct 27, 2021 |
| CVE-2021-29774 | IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025. | HIGH | 7.5 | Oct 27, 2021 |
| CVE-2021-29713 | IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt… | MEDIUM | 5.4 | Oct 27, 2021 |
| CVE-2021-29673 | IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt… | MEDIUM | 5.4 | Oct 27, 2021 |
| CVE-2020-5004 | IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte… | MEDIUM | 5.4 | Jul 28, 2021 |
| CVE-2020-4974 | IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from… | MEDIUM | 6.3 | Jul 28, 2021 |
| CVE-2021-20507 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 5.4 | Jul 19, 2021 |
| CVE-2020-5031 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 5.4 | Jul 19, 2021 |
| CVE-2021-29670 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-29668 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20371 | IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser… | MEDIUM | 6.5 | Jun 2, 2021 |
| CVE-2021-20348 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20347 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20346 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20345 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20343 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unautho… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2021-20338 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2020-5030 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2020-4977 | IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript… | MEDIUM | 5.4 | Jun 2, 2021 |
| CVE-2020-4732 | IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-… | MEDIUM | 6.5 | Jun 2, 2021 |
| CVE-2020-4495 | IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a… | HIGH | 8.8 | Jun 2, 2021 |
| CVE-2021-20519 | IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt… | MEDIUM | 5.4 | Apr 12, 2021 |
| CVE-2020-4965 | IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-For… | HIGH | 7.5 | Apr 12, 2021 |
| CVE-2020-4964 | IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application wh… | MEDIUM | 4.3 | Apr 12, 2021 |
Showing 1 to 25 of 141 CVEs