cbcvebase.

Ibm Engineering Workflow Management vulnerabilities

50 known vulnerabilities affecting ibm/engineering_workflow_management.

Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM46

Vulnerabilities

Page 1 of 3
CVE-2021-29844P3HIGHCVSS 8.8v7.0v7.0.1+1 more2021-10-27
CVE-2021-29844 [HIGH] CWE-918 CVE-2021-29844: IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
nvd
CVE-2021-29774P3HIGHCVSS 7.5v6.0.6v6.0.6.1+3 more2021-10-27
CVE-2021-29774 [HIGH] CVE-2021-29774: IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.
nvd
CVE-2021-20502P3HIGHCVSS 7.1v7.0.0v7.0.1+2 more2021-03-30
CVE-2021-20502 [HIGH] CWE-611 CVE-2021-20502: IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when pr IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 198059.
nvd
CVE-2020-4965P3HIGHCVSS 7.5v7.0.0v7.0.1+2 more2021-04-12
CVE-2020-4965 [HIGH] CWE-327 CVE-2020-4965: IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192422.
nvd
CVE-2020-4974P3MEDIUMCVSS 6.3v7.0v7.0.1+1 more2021-07-28
CVE-2020-4974 [MEDIUM] CWE-918 CVE-2020-4974: IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 192434.
nvd
CVE-2021-29786P4MEDIUMCVSS 6.5v7.0v7.0.1+1 more2021-10-27
CVE-2021-29786 [MEDIUM] CWE-312 CVE-2021-29786: IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenti IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.
nvd
CVE-2024-51454P4MEDIUMCVSS 6.1v7.0.2v7.0.2-ifix001+59 more2026-06-22
CVE-2024-51454 [MEDIUM] CWE-644 CVE-2024-51454: IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-si
nvd
CVE-2025-33128P4MEDIUMCVSS 5.4v7.0.3v7.0.3-ifix001+29 more2026-06-22
CVE-2025-33128 [MEDIUM] CWE-79 CVE-2025-33128: IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ses
nvd
CVE-2020-4547P4MEDIUMCVSS 5.4v6.0.2v6.0.6+3 more2021-01-27
CVE-2020-4547 [MEDIUM] CWE-1021 CVE-2020-4547: IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the vict IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 183315.
nvd
CVE-2024-28793P4MEDIUMCVSS 5.4v7.0.2v7.0.3+1 more2024-05-28
CVE-2024-28793 [MEDIUM] CWE-79 CVE-2024-28793: IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Un IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configurations, this vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 286830.
nvd
CVE-2020-4857P4MEDIUMCVSS 5.4v7.0v7.0.1+1 more2021-03-04
CVE-2020-4857 [MEDIUM] CWE-79 CVE-2020-4857: IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows us IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190460.
nvd
CVE-2021-20357P4MEDIUMCVSS 5.4v6.0.2v6.0.6+3 more2021-01-27
CVE-2021-20357 [MEDIUM] CWE-79 CVE-2021-20357: IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194963.
nvd
CVE-2020-4524P4MEDIUMCVSS 5.4v6.0.2v6.0.6+3 more2021-01-27
CVE-2020-4524 [MEDIUM] CWE-79 CVE-2020-4524: IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182434.
nvd
CVE-2020-4865P4MEDIUMCVSS 5.4v6.0.2v6.0.6+3 more2021-01-27
CVE-2020-4865 [MEDIUM] CWE-79 CVE-2020-4865: IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741.
nvd
CVE-2020-4855P4MEDIUMCVSS 5.4v6.0.2v6.0.6+3 more2021-01-27
CVE-2020-4855 [MEDIUM] CWE-79 CVE-2020-4855: IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190457.
nvd
CVE-2021-20519P4MEDIUMCVSS 5.4v7.0.0v7.0.1+2 more2021-04-12
CVE-2021-20519 [MEDIUM] CWE-79 CVE-2021-20519: IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows user IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198441.
nvd
CVE-2020-4920P4MEDIUMCVSS 5.4v7.0.0v7.0.1+2 more2021-04-12
CVE-2020-4920 [MEDIUM] CWE-79 CVE-2020-4920: IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allo IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191396.
nvd
CVE-2020-4445P4MEDIUMCVSS 5.4v7.0.0v7.0.1+1 more2020-09-02
CVE-2020-4445 [MEDIUM] CWE-79 CVE-2020-4445: IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability a IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 181122.
nvd
CVE-2020-4522P4MEDIUMCVSS 5.4v7.0.0v7.0.1+1 more2020-09-02
CVE-2020-4522 [MEDIUM] CWE-79 CVE-2020-4522: IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability a IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182397.
nvd
CVE-2020-4546P4MEDIUMCVSS 5.4v7.0.0v7.0.1+1 more2020-09-02
CVE-2020-4546 [MEDIUM] CWE-79 CVE-2020-4546: IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability a IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183314.
nvd