Skip to main content

Vendor/product archive

ibm / engineering_lifecycle_management CVEs

Beta · best-effort

48 CVEs tagged to ibm / engineering_lifecycle_management1 Critical, 5 High, 42 Medium, 0 Low, 0 Unrated.

CVE-2026-4051

Published May 26, 2026

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exposed method that is not proper…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3660

Published May 26, 2026

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthori…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3603

Published May 26, 2026

IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulner…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36033

Published Feb 3, 2026

IBM Engineering Lifecycle Management - Global Configuration Management 7.0.3 through 7.0.3 Interim Fix 017, and 7.1.0 through 7.1.0 Interim Fix 004 IBM Global Configuration Manage…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29670

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

CVSS 5.4 · Medium

CVE-2021-29668

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

CVSS 5.4 · Medium

CVE-2021-20371

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information c…

CVSS 6.5 · Medium

CVE-2021-20348

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from…

CVSS 5.4 · Medium

CVE-2021-20347

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from…

CVSS 5.4 · Medium

CVE-2021-20346

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from…

CVSS 5.4 · Medium

CVE-2021-20345

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from…

CVSS 5.4 · Medium

CVE-2021-20343

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from…

CVSS 5.4 · Medium

CVE-2021-20338

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

CVSS 5.4 · Medium

CVE-2020-5030

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

CVSS 5.4 · Medium

CVE-2020-4977

Published Jun 2, 2021

IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

CVSS 5.4 · Medium

CVE-2020-4732

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126.

CVSS 6.5 · Medium

CVE-2020-4495

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted r…

CVSS 8.8 · High

CVE-2021-20520

Published Mar 30, 2021

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fu…

CVSS 5.4 · Medium

CVE-2021-20518

Published Mar 30, 2021

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fu…

CVSS 5.4 · Medium

CVE-2021-20506

Published Mar 30, 2021

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fu…

CVSS 5.4 · Medium
Showing 1-25 of 48 CVEsPage 1 of 2