VendorsIBMengineering_lifecycle_optimization7.0.2
Vulnerabilities

IBM Engineering Lifecycle Optimization 7.0.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2023-45187
IBM Engineering Lifecycle Optimization - Publishing session fixation
Published 2024-02-09 · Modified
8.8EPSS 0.004
CVE-2021-29774
IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.
Published 2021-10-27 · Modified
7.5EPSS 0.010
CVE-2023-45191
IBM Engineering Lifecycle Optimization information disclosure
Published 2024-02-09 · Modified
7.5EPSS 0.007
CVE-2021-29786
IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.
Published 2021-10-27 · Modified
6.5EPSS 0.006
CVE-2023-45190
IBM Engineering Lifecycle Optimization HTTP header injection
Published 2024-02-09 · Modified
6.1EPSS 0.003
CVE-2024-52890
IBM Engineering Lifecycle Optimization - Publishing cross-site scripting
Published 2025-08-05 · Analyzed
6.1EPSS 0.002
CVE-2020-5031
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193738.
Published 2021-07-19 · Modified
5.4EPSS 0.005
CVE-2021-20507
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198235.
Published 2021-07-19 · Modified
5.4EPSS 0.005
CVE-2021-29673
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199482.
Published 2021-10-27 · Modified
5.4EPSS 0.005
CVE-2021-29713
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published 2021-10-27 · Modified
5.4EPSS 0.005