IBM Engineering Lifecycle Optimization Publishing
By the Year
In 2024 there have been 0 vulnerabilities in IBM Engineering Lifecycle Optimization Publishing . Engineering Lifecycle Optimization Publishing did not have any published security vulnerabilities last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2024 | 0 | 0.00 |
2023 | 0 | 0.00 |
2022 | 0 | 0.00 |
2021 | 13 | 5.83 |
2020 | 0 | 0.00 |
2019 | 0 | 0.00 |
2018 | 0 | 0.00 |
It may take a day or so for new Engineering Lifecycle Optimization Publishing vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Engineering Lifecycle Optimization Publishing Security Vulnerabilities
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting
CVE-2021-29670
5.4 - Medium
- June 02, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199408.
XSS
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting
CVE-2021-29668
5.4 - Medium
- June 02, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199406.
XSS
IBM Jazz Foundation and IBM Engineering products could
CVE-2021-20371
6.5 - Medium
- June 02, 2021
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195516.
Generation of Error Message Containing Sensitive Information
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF)
CVE-2021-20348
5.4 - Medium
- June 02, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-ForceID: 194597.
XSPA
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF)
CVE-2021-20347
5.4 - Medium
- June 02, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194596.
XSPA
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF)
CVE-2021-20346
5.4 - Medium
- June 02, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194595.
XSPA
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF)
CVE-2021-20345
5.4 - Medium
- June 02, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194594.
XSPA
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF)
CVE-2021-20343
5.4 - Medium
- June 02, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194593.
XSPA
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting
CVE-2021-20338
5.4 - Medium
- June 02, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194449.
XSS
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting
CVE-2020-5030
5.4 - Medium
- June 02, 2021
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193737.
XSS
IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting
CVE-2020-4977
5.4 - Medium
- June 02, 2021
IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192470.
XSS
IBM Jazz Foundation and IBM Engineering products could
CVE-2020-4732
6.5 - Medium
- June 02, 2021
IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126.
Information Disclosure
IBM Jazz Foundation and IBM Engineering products could
CVE-2020-4495
8.8 - High
- June 02, 2021
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions, and execute arbitrary actions with administrative privileges. IBM X-Force ID: 182114.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for IBM Removable Media Manager or by IBM? Click the Watch button to subscribe.