cbcvebase.

Ibm Jazz For Service Management vulnerabilities

28 known vulnerabilities affecting ibm/jazz_for_service_management.

Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM22

Vulnerabilities

Page 2 of 2
CVE-2021-29814P4MEDIUMCVSS 5.4v1.1.3.102021-09-23
CVE-2021-29814 [MEDIUM] CWE-79 CVE-2021-29814: IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204334.
nvd
CVE-2021-29810P4MEDIUMCVSS 5.4v1.1.3.102021-09-23
CVE-2021-29810 [MEDIUM] CWE-79 CVE-2021-29810: IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204279.
nvd
CVE-2022-35722P4MEDIUMCVSS 5.4fixed in 1.1.3.16v1.1.32022-09-28
CVE-2022-35722 [MEDIUM] CWE-79 CVE-2022-35722: IBM Jazz for Service Management is vulnerable to stored cross-site scripting. This vulnerability all IBM Jazz for Service Management is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 231381.
nvd
CVE-2019-4718P4MEDIUMCVSS 5.4v1.1.3.0v3.132020-03-23
CVE-2019-4718 [MEDIUM] CWE-79 CVE-2019-4718: IBM Jazz for Service Management 3.13 is vulnerable to cross-site scripting. This vulnerability allow IBM Jazz for Service Management 3.13 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172123.
nvd
CVE-2021-29904P4MEDIUMCVSS 5.5v1.1.3.102021-09-23
CVE-2021-29904 [MEDIUM] CWE-312 CVE-2021-29904: IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credential IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 207610.
nvd
CVE-2019-4194P4MEDIUMCVSS 4.3≥ 1.1.3.0, ≤ 1.1.3.2v1.1.3+2 more2019-07-17
CVE-2019-4194 [MEDIUM] CVE-2019-4194: IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 is missing function level access control IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 is missing function level access control that could allow a user to delete authorized resources. IBM X-Force ID: 159033.
nvd
CVE-2025-36011P4MEDIUMCVSS 4.3≥ 1.1.3.0, < 1.1.3.25≥ 1.1.3.0, ≤ 1.1.3.242025-09-09
CVE-2025-36011 [MEDIUM] CWE-614 CVE-2025-36011: IBM Jazz for Service Management 1.1.3.0 through 1.1.3.24 does not set the secure attribute on author IBM Jazz for Service Management 1.1.3.0 through 1.1.3.24 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain th
nvd
CVE-2019-4275P4MEDIUMCVSS 5.5v1.1.3v1.1.3.1+1 more2019-08-02
CVE-2019-4275 [MEDIUM] CVE-2019-4275: IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow an unauthorized local user t IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow an unauthorized local user to create unique catalog names that could cause a denial of service. IBM X-Force ID: 160296.
nvd
Ibm Jazz For Service Management vulnerabilities | cvebase