CVE-2021-20502 vulnerability in IBM Products
Published on March 30, 2021
IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 198059.
Products Associated with CVE-2021-20502
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2021-20502 are published in these products:
Affected Versions
IBM Engineering Lifecycle Optimization:- Version 7.0 is affected.
- Version 7.0.1 is affected.
- Version 7.0.2 is affected.
- Version 7.0 is affected.
- Version 7.0.1 is affected.
- Version 7.0.2 is affected.
- Version 6.0.2 is affected.
- Version 6.0.6 is affected.
- Version 6.0.6.1 is affected.
- Version 6.0.2 is affected.
- Version 6.0.6 is affected.
- Version 6.0.6.1 is affected.
Exploit Probability
EPSS
0.27%
Percentile
50.46%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.