Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Rational_engineering_lifecycle_manager
(Ibm)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 141 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-06-02 | CVE-2021-20346 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194595. | Collaborative_lifecycle_management, Engineering_lifecycle_management, Engineering_lifecycle_optimization_\-_engineering_insights, Engineering_lifecycle_optimization_\-_publishing, Engineering_test_management, Rational_doors_next_generation, Rational_engineering_lifecycle_manager, Rational_quality_manager, Removable_media_manager | 5.4 | ||
2021-06-02 | CVE-2021-20348 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-ForceID: 194597. | Collaborative_lifecycle_management, Engineering_lifecycle_management, Engineering_lifecycle_optimization_\-_engineering_insights, Engineering_lifecycle_optimization_\-_publishing, Engineering_test_management, Rational_doors_next_generation, Rational_engineering_lifecycle_manager, Rational_quality_manager, Removable_media_manager | 5.4 | ||
2021-06-02 | CVE-2021-20371 | IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195516. | Collaborative_lifecycle_management, Engineering_lifecycle_management, Engineering_lifecycle_optimization_\-_engineering_insights, Engineering_lifecycle_optimization_\-_publishing, Engineering_test_management, Rational_doors_next_generation, Rational_engineering_lifecycle_manager, Rational_quality_manager, Removable_media_manager | 6.5 | ||
2021-06-02 | CVE-2021-29670 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199408. | Collaborative_lifecycle_management, Engineering_lifecycle_management, Engineering_lifecycle_optimization_\-_engineering_insights, Engineering_lifecycle_optimization_\-_publishing, Engineering_test_management, Rational_doors_next_generation, Rational_engineering_lifecycle_manager, Rational_quality_manager, Removable_media_manager | 5.4 | ||
2021-06-02 | CVE-2021-29668 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199406. | Collaborative_lifecycle_management, Engineering_lifecycle_management, Engineering_lifecycle_optimization_\-_engineering_insights, Engineering_lifecycle_optimization_\-_publishing, Engineering_test_management, Rational_doors_next_generation, Rational_engineering_lifecycle_manager, Rational_quality_manager, Removable_media_manager | 5.4 | ||
2021-04-12 | CVE-2021-20519 | IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198441. | Collaborative_lifecycle_management, Doors_next, Engineering_insights, Engineering_lifecycle_management, Engineering_requirements_management_doors_next, Engineering_test_management, Engineering_workflow_management, Rational_engineering_lifecycle_manager, Rational_quality_manager, Rational_team_concert, Removable_media_management, Rhapsody_model_manager | 5.4 | ||
2021-04-12 | CVE-2020-4964 | IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users. IBM X-Force ID: 192419. | Collaborative_lifecycle_management, Doors_next, Engineering_insights, Engineering_lifecycle_management, Engineering_requirements_management_doors_next, Engineering_test_management, Engineering_workflow_management, Rational_engineering_lifecycle_manager, Rational_quality_manager, Rational_team_concert, Removable_media_management, Rhapsody_model_manager | 4.3 | ||
2021-04-12 | CVE-2020-4920 | IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191396. | Collaborative_lifecycle_management, Doors_next, Engineering_insights, Engineering_lifecycle_management, Engineering_requirements_management_doors_next, Engineering_test_management, Engineering_workflow_management, Rational_engineering_lifecycle_manager, Rational_quality_manager, Rational_team_concert, Removable_media_management, Rhapsody_model_manager | 5.4 | ||
2021-03-30 | CVE-2021-20520 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198572. | Engineering_insights, Engineering_lifecycle_management, Engineering_requirements_quality_assistant_on\-Premises, Engineering_workflow_management, Rational_engineering_lifecycle_manager, Rational_team_concert | 5.4 | ||
2021-03-30 | CVE-2021-20518 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198437. | Engineering_insights, Engineering_lifecycle_management, Engineering_requirements_quality_assistant_on\-Premises, Engineering_workflow_management, Rational_engineering_lifecycle_manager, Rational_team_concert | 5.4 |