Skip to main content

Vendor/product archive

ibm / engineering_test_management CVEs

Beta · best-effort

45 CVEs tagged to ibm / engineering_test_management0 Critical, 2 High, 43 Medium, 0 Low, 0 Unrated.

CVE-2023-43054

Published Mar 3, 2024

IBM Engineering Test Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29670

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

CVSS 5.4 · Medium

CVE-2021-29668

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

CVSS 5.4 · Medium

CVE-2021-20371

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information c…

CVSS 6.5 · Medium

CVE-2021-20348

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from…

CVSS 5.4 · Medium

CVE-2021-20347

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from…

CVSS 5.4 · Medium

CVE-2021-20346

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from…

CVSS 5.4 · Medium

CVE-2021-20345

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from…

CVSS 5.4 · Medium

CVE-2021-20343

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from…

CVSS 5.4 · Medium

CVE-2021-20338

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

CVSS 5.4 · Medium

CVE-2020-5030

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

CVSS 5.4 · Medium

CVE-2020-4977

Published Jun 2, 2021

IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…

CVSS 5.4 · Medium

CVE-2020-4732

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126.

CVSS 6.5 · Medium

CVE-2020-4495

Published Jun 2, 2021

IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted r…

CVSS 8.8 · High

CVE-2021-20351

Published Mar 4, 2021

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functi…

CVSS 5.4 · Medium

CVE-2021-20350

Published Mar 4, 2021

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functi…

CVSS 5.4 · Medium

CVE-2021-20340

Published Mar 4, 2021

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functi…

CVSS 5.4 · Medium

CVE-2020-4975

Published Mar 4, 2021

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functi…

CVSS 5.4 · Medium
Showing 1-25 of 45 CVEsPage 1 of 2