CVE-2021-29865

CWE-1021Clickjacking3 documents3 sources
Severity
5.4MEDIUM
EPSS
0.1%
top 76.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 24
Latest updateJun 25

Description

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 206091.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

CVEListV5ibm/jazz_team_server5 versions+4
NVDibm/jazz_team_server5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2678-mh77-mjgv: IBM Jazz Team Server 62022-06-25
CVEList
CVE-2021-29865: IBM Jazz Team Server 62022-06-24
CVE-2021-29865 (MEDIUM CVSS 5.4) | IBM Jazz Team Server 6.0.6 | cvebase.io