Show filters
187 Total Results
Displaying 31-40 of 187
Sort by:
Attacker Value
Unknown

CVE-2021-29668

Disclosure Date: June 01, 2021 (last updated February 22, 2025)
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199406.
Attacker Value
Unknown

CVE-2020-4977

Disclosure Date: June 01, 2021 (last updated February 22, 2025)
IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192470.
Attacker Value
Unknown

CVE-2021-20343

Disclosure Date: June 01, 2021 (last updated February 22, 2025)
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194593.
Attacker Value
Unknown

CVE-2020-5030

Disclosure Date: June 01, 2021 (last updated February 22, 2025)
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193737.
Attacker Value
Unknown

CVE-2021-31584

Disclosure Date: April 23, 2021 (last updated February 22, 2025)
Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks for actions with administrative privileges.
Attacker Value
Unknown

CVE-2021-31583

Disclosure Date: April 23, 2021 (last updated February 22, 2025)
Sipwise C5 NGCP WWW Admin version 3.6.7 up to and including platform version NGCP CE 3.0 has multiple authenticated stored and reflected XSS vulnerabilities when input passed via several parameters to several scripts is not properly sanitized before being returned to the user: Stored XSS in callforward/time/set/save (POST tsetname); Reflected XSS in addressbook (GET filter); Stored XSS in addressbook/save (POST firstname, lastname, company); and Reflected XSS in statistics/versions (GET lang).
Attacker Value
Unknown

CVE-2021-21626

Disclosure Date: March 18, 2021 (last updated February 22, 2025)
Jenkins Warnings Next Generation Plugin 8.4.4 and earlier does not perform a permission check in methods implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-specified file patterns match workspace contents.
Attacker Value
Unknown

CVE-2020-4856

Disclosure Date: February 26, 2021 (last updated February 22, 2025)
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190459.
Attacker Value
Unknown

CVE-2020-4975

Disclosure Date: February 26, 2021 (last updated February 22, 2025)
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192435.
Attacker Value
Unknown

CVE-2021-20350

Disclosure Date: February 26, 2021 (last updated February 22, 2025)
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194707.