cbcvebase.

Ibm Jazz For Service Management vulnerabilities

28 known vulnerabilities affecting ibm/jazz_for_service_management.

Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM22

Vulnerabilities

Page 1 of 2
CVE-2021-29831P3HIGHCVSS 8.1v1.1.3.102021-09-21
CVE-2021-29831 [HIGH] CWE-611 CVE-2021-29831: IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 204775.
nvd
CVE-2023-46186P3HIGHCVSS 7.5v1.1.3.202024-02-14
CVE-2023-46186 [HIGH] CWE-425 CVE-2023-46186: IBM Jazz for Service Management 1.1.3.20 could allow an unauthorized user to obtain sensitive file i IBM Jazz for Service Management 1.1.3.20 could allow an unauthorized user to obtain sensitive file information using forced browsing due to improper access controls. IBM X-Force ID: 269929.
nvd
CVE-2019-4193P3HIGHCVSS 7.5≥ 1.1.3, ≤ 1.1.3.2v1.1.3+1 more2019-07-11
CVE-2019-4193 [HIGH] CWE-200 CVE-2019-4193: IBM Jazz for Service Management 1.1.3 and 1.1.3.2 stores sensitive information in URL parameters. Th IBM Jazz for Service Management 1.1.3 and 1.1.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-force ID: 159032.
nvd
CVE-2024-47106P3HIGHCVSS 7.5≥ 1.1.3, ≤ 1.1.3.222025-01-18
CVE-2024-47106 [HIGH] CWE-552 CVE-2024-47106: IBM Jazz for Service Management 1.1.3 through 1.1.3.22 could allow a remote attacker to obtain sensi IBM Jazz for Service Management 1.1.3 through 1.1.3.22 could allow a remote attacker to obtain sensitive information from improper access restrictions that could aid in further attacks against the system.
nvd
CVE-2017-1631P3HIGHCVSS 8.8v1.1.32017-12-20
CVE-2017-1631 [HIGH] CWE-352 CVE-2017-1631: IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request fo IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 133140.
nvd
CVE-2017-1746P3HIGHCVSS 8.8v1.1.32017-12-20
CVE-2017-1746 [HIGH] CWE-352 CVE-2017-1746: IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request fo IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 135519.
nvd
CVE-2019-4186P4MEDIUMCVSS 6.1v1.1.32019-09-05
CVE-2019-4186 [MEDIUM] CWE-79 CVE-2019-4186: IBM Jazz for Service Management 1.1.3 is vulnerable to HTTP header injection, caused by incorrect tr IBM Jazz for Service Management 1.1.3 is vulnerable to HTTP header injection, caused by incorrect trust in the HTTP Host header during caching. By sending a specially crafted HTTP GET request, a remote attacker could exploit this vulnerability to inject arbitrary HTTP headers, which will allow the attacker to conduct various attacks against the vulnera
nvd
CVE-2021-29816P4MEDIUMCVSS 6.5v1.1.3.102021-09-23
CVE-2021-29816 [MEDIUM] CWE-352 CVE-2021-29816: IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-s IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204341.
nvd
CVE-2025-36249P4MEDIUMCVSS 5.3≥ 1.1.3.0, < 1.1.3.26≥ 1.1.3.0, ≤ 1.1.3.252025-10-31
CVE-2025-36249 [MEDIUM] CWE-614 CVE-2025-36249: IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on author IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain th
nvd
CVE-2024-52892P4MEDIUMCVSS 6.1≥ 1.1.3, < 1.1.3.24≥ 1.1.3, ≤ 1.1.3.232025-02-06
CVE-2024-52892 [MEDIUM] CWE-79 CVE-2024-52892: IBM Jazz for Service Management 1.1.3 through 1.1.3.23 is vulnerable to cross-site scripting. This v IBM Jazz for Service Management 1.1.3 through 1.1.3.23 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2019-4201P4MEDIUMCVSS 6.1≥ 1.1.3, ≤ 1.1.3.2v1.1.3+2 more2019-06-06
CVE-2019-4201 [MEDIUM] CWE-601 CVE-2019-4201: IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow a remote attacker to conduct IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to
nvd
CVE-2022-35721P4MEDIUMCVSS 5.4v1.1.32022-09-23
CVE-2022-35721 [MEDIUM] CWE-79 CVE-2022-35721: IBM Jazz for Service Management 1.1.3 is vulnerable to stored cross-site scripting. This vulnerabili IBM Jazz for Service Management 1.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 231380.
nvd
CVE-2021-29832P4MEDIUMCVSS 5.4v1.1.3.102021-09-23
CVE-2021-29832 [MEDIUM] CWE-79 CVE-2021-29832: IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204824.
nvd
CVE-2021-29815P4MEDIUMCVSS 5.4v1.1.3.102021-09-23
CVE-2021-29815 [MEDIUM] CWE-79 CVE-2021-29815: IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204340.
nvd
CVE-2021-29833P4MEDIUMCVSS 5.4v1.1.3.102021-09-23
CVE-2021-29833 [MEDIUM] CWE-79 CVE-2021-29833: IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204825.
nvd
CVE-2021-29813P4MEDIUMCVSS 5.4v1.1.3.102021-09-23
CVE-2021-29813 [MEDIUM] CWE-79 CVE-2021-29813: IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204331.
nvd
CVE-2021-38877P4MEDIUMCVSS 5.4v1.1.3.102021-09-23
CVE-2021-38877 [MEDIUM] CWE-79 CVE-2021-38877: IBM Jazz for Service Management 1.1.3.10 is vulnerable to stored cross-site scripting. This vulnerab IBM Jazz for Service Management 1.1.3.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208405.
nvd
CVE-2021-29905P4MEDIUMCVSS 5.4v1.1.3.102021-09-23
CVE-2021-29905 [MEDIUM] CWE-79 CVE-2021-29905: IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-s IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 207616.
nvd
CVE-2021-29800P4MEDIUMCVSS 5.4v1.1.3.102021-09-23
CVE-2021-29800 [MEDIUM] CWE-79 CVE-2021-29800: IBM Tivoli Netcool/OMNIbus_GUI and IBM Jazz for Service Management 1.1.3.10 is vulnerable to stored IBM Tivoli Netcool/OMNIbus_GUI and IBM Jazz for Service Management 1.1.3.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2021-29812P4MEDIUMCVSS 5.4v1.1.3.102021-09-23
CVE-2021-29812 [MEDIUM] CWE-79 CVE-2021-29812: IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204330.
nvd
Ibm Jazz For Service Management vulnerabilities | cvebase