CVE-2020-5030
- EPSS 0.21%
- Veröffentlicht 02.06.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 05:33:34
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disc...
CVE-2020-4977
- EPSS 0.19%
- Veröffentlicht 02.06.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 05:33:30
IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credent...
CVE-2020-4732
- EPSS 0.21%
- Veröffentlicht 02.06.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 05:33:11
IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126.
- EPSS 1.51%
- Veröffentlicht 02.06.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 05:32:48
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to...
CVE-2021-20519
- EPSS 0.16%
- Veröffentlicht 12.04.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:46:42
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tru...
CVE-2020-4965
- EPSS 0.11%
- Veröffentlicht 12.04.2021 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:33:29
IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192422.
CVE-2020-4964
- EPSS 0.15%
- Veröffentlicht 12.04.2021 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:33:28
IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users. IBM X-Force ID: 192419.
CVE-2020-4920
- EPSS 0.13%
- Veröffentlicht 12.04.2021 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:33:25
IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure withi...
CVE-2021-20357
- EPSS 0.16%
- Veröffentlicht 27.01.2021 17:15:14
- Zuletzt bearbeitet 21.11.2024 05:46:27
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust...
CVE-2020-4865
- EPSS 0.21%
- Veröffentlicht 27.01.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:33:20
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust...