Ibm Engineering Lifecycle Management vulnerabilities
50 known vulnerabilities affecting ibm/engineering_lifecycle_management.
Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH5MEDIUM43
Vulnerabilities
Page 2 of 3
CVE-2020-4865P4MEDIUMCVSS 5.4v7.02021-01-27
CVE-2020-4865 [MEDIUM] CWE-79 CVE-2020-4865: IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741.
nvd
CVE-2020-4855P4MEDIUMCVSS 5.4v7.02021-01-27
CVE-2020-4855 [MEDIUM] CWE-79 CVE-2020-4855: IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190457.
nvd
CVE-2021-20519P4MEDIUMCVSS 5.4v7.0.0v7.0.1+1 more2021-04-12
CVE-2021-20519 [MEDIUM] CWE-79 CVE-2021-20519: IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows user
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198441.
nvd
CVE-2020-4920P4MEDIUMCVSS 5.4v7.0.0v7.0.1+1 more2021-04-12
CVE-2020-4920 [MEDIUM] CWE-79 CVE-2020-4920: IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allo
IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191396.
nvd
CVE-2020-4733P4MEDIUMCVSS 5.4v7.0v7.0.12021-01-08
CVE-2020-4733 [MEDIUM] CWE-79 CVE-2020-4733: IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188127.
nvd
CVE-2020-4697P4MEDIUMCVSS 5.4v7.0v7.0.12021-01-08
CVE-2020-4697 [MEDIUM] CWE-79 CVE-2020-4697: IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186790.
nvd
CVE-2020-4691P4MEDIUMCVSS 5.4v7.0v7.0.12021-01-08
CVE-2020-4691 [MEDIUM] CWE-79 CVE-2020-4691: IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186698.
nvd
CVE-2020-4856P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-03-04
CVE-2020-4856 [MEDIUM] CWE-79 CVE-2020-4856: IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows us
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190459.
nvd
CVE-2020-4863P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-03-04
CVE-2020-4863 [MEDIUM] CWE-79 CVE-2020-4863: IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows us
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190566.
nvd
CVE-2021-29668P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-06-02
CVE-2021-29668 [MEDIUM] CWE-79 CVE-2021-29668: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199406.
nvd
CVE-2020-5030P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-06-02
CVE-2020-5030 [MEDIUM] CWE-79 CVE-2020-5030: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193737.
nvd
CVE-2021-20338P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-06-02
CVE-2021-20338 [MEDIUM] CWE-79 CVE-2021-20338: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194449.
nvd
CVE-2021-29670P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-06-02
CVE-2021-29670 [MEDIUM] CWE-79 CVE-2021-29670: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199408.
nvd
CVE-2020-4977P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-06-02
CVE-2020-4977 [MEDIUM] CWE-79 CVE-2020-4977: IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. Th
IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192470.
nvd
CVE-2021-20350P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-03-04
CVE-2021-20350 [MEDIUM] CWE-79 CVE-2021-20350: IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194707.
nvd
CVE-2021-20351P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-03-04
CVE-2021-20351 [MEDIUM] CWE-79 CVE-2021-20351: IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194708.
nvd
CVE-2021-20340P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-03-04
CVE-2021-20340 [MEDIUM] CWE-79 CVE-2021-20340: IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194451.
nvd
CVE-2020-4975P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-03-04
CVE-2020-4975 [MEDIUM] CWE-79 CVE-2020-4975: IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192435.
nvd
CVE-2020-4866P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-03-04
CVE-2020-4866 [MEDIUM] CWE-79 CVE-2020-4866: IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190742.
nvd
CVE-2021-20352P4MEDIUMCVSS 5.4v7.02021-03-30
CVE-2021-20352 [MEDIUM] CWE-79 CVE-2021-20352: IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194710.
nvd