Skip to main content

Vendor/product archive

ibm / engineering_lifecycle_optimization CVEs

Beta · best-effort

11 CVEs tagged to ibm / engineering_lifecycle_optimization0 Critical, 3 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2023-45191

Published Feb 9, 2024

IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-For…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45187

Published Feb 9, 2024

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29844

Published Oct 27, 2021

IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentia…

CVSS 8.8 · High

CVE-2021-29673

Published Oct 27, 2021

IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended f…

CVSS 5.4 · Medium

CVE-2021-20507

Published Jul 19, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

CVSS 5.4 · Medium

CVE-2020-5031

Published Jul 19, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

CVSS 5.4 · Medium
Showing 1-11 of 11 CVEsPage 1 of 1