cbcvebase.

Ibm Engineering Lifecycle Optimization Publishing vulnerabilities

37 known vulnerabilities affecting ibm/engineering_lifecycle_optimization_publishing.

Total CVEs
37
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH6MEDIUM30

Vulnerabilities

Page 2 of 2
CVE-2023-45190P4MEDIUMCVSS 6.1v7.0.2, 7.0.32024-02-09
CVE-2023-45190 [MEDIUM] CWE-307 CVE-2023-45190: IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, cause IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 268754.
nvd
CVE-2021-39028P4MEDIUMCVSS 5.4v6.0.6v6.0.6.1+3 more2022-07-14
CVE-2021-39028 [MEDIUM] CWE-74 CVE-2021-39028: IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnera IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X
nvd
CVE-2021-29668P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-06-02
CVE-2021-29668 [MEDIUM] CWE-79 CVE-2021-29668: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199406.
nvd
CVE-2020-5030P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-06-02
CVE-2020-5030 [MEDIUM] CWE-79 CVE-2020-5030: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193737.
nvd
CVE-2021-20338P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-06-02
CVE-2021-20338 [MEDIUM] CWE-79 CVE-2021-20338: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194449.
nvd
CVE-2021-29670P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-06-02
CVE-2021-29670 [MEDIUM] CWE-79 CVE-2021-29670: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199408.
nvd
CVE-2020-4977P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-06-02
CVE-2020-4977 [MEDIUM] CWE-79 CVE-2020-4977: IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. Th IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192470.
nvd
CVE-2021-39015P4MEDIUMCVSS 5.4v6.0.6v6.0.6.1+3 more2022-07-14
CVE-2021-39015 [MEDIUM] CWE-79 CVE-2021-39015: IBM Engineering Lifecycle Optimization - Publishing 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-sit IBM Engineering Lifecycle Optimization - Publishing 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213655.
nvd
CVE-2018-1951P4MEDIUMCVSS 5.4v2.1.2v6.0.5+1 more2019-01-04
CVE-2018-1951 [MEDIUM] CWE-79 CVE-2018-1951: IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerabil IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153494.
nvd
CVE-2018-1657P4MEDIUMCVSS 5.4v2.1.2v6.0.5+1 more2019-01-04
CVE-2018-1657 [MEDIUM] CWE-79 CVE-2018-1657: IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerabil IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 144883.
nvd
CVE-2018-1534P4MEDIUMCVSS 5.4v6.0.5v6.0.62018-10-12
CVE-2018-1534 [MEDIUM] CWE-79 CVE-2018-1534: IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerabi IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142432.
nvd
CVE-2018-1533P4MEDIUMCVSS 5.4v6.0.5v6.0.62018-10-12
CVE-2018-1533 [MEDIUM] CWE-79 CVE-2018-1533: IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerabi IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142431.
nvd
CVE-2019-4431P4MEDIUMCVSS 5.4v6.0.6v6.0.6.12020-02-12
CVE-2019-4431 [MEDIUM] CWE-79 CVE-2019-4431: IBM Rational Publishing Engine 6.0.6 and 6.0.6.1 is vulnerable to cross-site scripting. This vulnera IBM Rational Publishing Engine 6.0.6 and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162888.
nvd
CVE-2016-2912P4MEDIUMCVSS 5.4v2.0.12016-08-08
CVE-2016-2912 [MEDIUM] CWE-79 CVE-2016-2912: Cross-site scripting (XSS) vulnerability in the Document Builder in IBM Rational Publishing Engine ( Cross-site scripting (XSS) vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2020-4316P4MEDIUMCVSS 4.7v6.0.6v6.0.6.1+1 more2020-07-16
CVE-2020-4316 [MEDIUM] CVE-2020-4316: IBM Publishing Engine 6.0.6, 6.0.6.1, and 7.0 does not set the secure attribute on authorization tok IBM Publishing Engine 6.0.6, 6.0.6.1, and 7.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by sno
nvd
CVE-2021-39016P4MEDIUMCVSS 4.3v6.0.6v6.0.6.1+3 more2022-07-14
CVE-2021-39016 [MEDIUM] CVE-2021-39016: IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 does not s IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 does not sufficiently monitor or control transmitted network traffic volume, so that an actor can cause the software to transmit more traffic than should be allowed for that actor. IBM X-Force ID: 213722.
nvd
CVE-2021-39018P4MEDIUMCVSS 4.3v6.0.6v6.0.6.1+3 more2022-07-14
CVE-2021-39018 [MEDIUM] CWE-209 CVE-2021-39018: IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disc IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose sensitive information in a SQL error message that could aid in further attacks against the system. IBM X-Force ID: 213726.
nvd
Ibm Engineering Lifecycle Optimization Publishing vulnerabilities | cvebase