Show filters
39 Total Results
Displaying 11-20 of 39
Sort by:
Attacker Value
Unknown

CVE-2021-20507

Disclosure Date: July 16, 2021 (last updated February 23, 2025)
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198235.
Attacker Value
Unknown

CVE-2021-20519

Disclosure Date: April 09, 2021 (last updated February 22, 2025)
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198441.
Attacker Value
Unknown

CVE-2020-4964

Disclosure Date: April 09, 2021 (last updated November 28, 2024)
IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users. IBM X-Force ID: 192419.
Attacker Value
Unknown

CVE-2020-4920

Disclosure Date: April 09, 2021 (last updated February 22, 2025)
IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191396.
Attacker Value
Unknown

CVE-2020-4965

Disclosure Date: April 09, 2021 (last updated February 22, 2025)
IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192422.
Attacker Value
Unknown

CVE-2021-20518

Disclosure Date: March 29, 2021 (last updated February 22, 2025)
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198437.
Attacker Value
Unknown

CVE-2021-20520

Disclosure Date: March 29, 2021 (last updated February 22, 2025)
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198572.
Attacker Value
Unknown

CVE-2021-20503

Disclosure Date: March 29, 2021 (last updated February 22, 2025)
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198182.
Attacker Value
Unknown

CVE-2021-20502

Disclosure Date: March 29, 2021 (last updated February 22, 2025)
IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 198059.
Attacker Value
Unknown

CVE-2021-20506

Disclosure Date: March 29, 2021 (last updated February 22, 2025)
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198231.