Engineering Lifecycle Optimization Engineering Insights IBM Engineering Lifecycle Optimization Engineering Insights

Do you want an email whenever new security vulnerabilities are reported in IBM Engineering Lifecycle Optimization Engineering Insights?

By the Year

In 2021 there have been 13 vulnerabilities in IBM Engineering Lifecycle Optimization Engineering Insights with an average score of 5.8 out of ten. Engineering Lifecycle Optimization Engineering Insights did not have any published security vulnerabilities last year. That is, 13 more vulnerabilities have already been reported in 2021 as compared to last year.

Year Vulnerabilities Average Score
2021 13 5.83
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Engineering Lifecycle Optimization Engineering Insights vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM Engineering Lifecycle Optimization Engineering Insights Security Vulnerabilities

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting

CVE-2021-29670 5.4 - Medium - June 02, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199408.

XSS

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting

CVE-2021-29668 5.4 - Medium - June 02, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199406.

XSS

IBM Jazz Foundation and IBM Engineering products could

CVE-2021-20371 6.5 - Medium - June 02, 2021

IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195516.

Generation of Error Message Containing Sensitive Information

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF)

CVE-2021-20348 5.4 - Medium - June 02, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-ForceID: 194597.

XSPA

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF)

CVE-2021-20347 5.4 - Medium - June 02, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194596.

XSPA

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF)

CVE-2021-20346 5.4 - Medium - June 02, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194595.

XSPA

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF)

CVE-2021-20345 5.4 - Medium - June 02, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194594.

XSPA

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF)

CVE-2021-20343 5.4 - Medium - June 02, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194593.

XSPA

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting

CVE-2021-20338 5.4 - Medium - June 02, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194449.

XSS

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting

CVE-2020-5030 5.4 - Medium - June 02, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193737.

XSS

IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting

CVE-2020-4977 5.4 - Medium - June 02, 2021

IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192470.

XSS

IBM Jazz Foundation and IBM Engineering products could

CVE-2020-4732 6.5 - Medium - June 02, 2021

IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126.

Information Disclosure

IBM Jazz Foundation and IBM Engineering products could

CVE-2020-4495 8.8 - High - June 02, 2021

IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions, and execute arbitrary actions with administrative privileges. IBM X-Force ID: 182114.

AuthZ

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for IBM Removable Media Manager or by IBM? Click the Watch button to subscribe.

IBM
Vendor

subscribe