VendorsIBMengineering_workflow_managementall versions
Vulnerabilities

IBM Engineering Workflow Management

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2021-20507
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198235.
Published 2021-07-19 · Modified
5.4EPSS 0.005
CVE-2020-5031
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193738.
Published 2021-07-19 · Modified
5.4EPSS 0.005
CVE-2024-28793
IBM Engineering Workflow Management cross-site scripting
Published 2024-05-28 · Analyzed
5.4EPSS 0.003
CVE-2025-33128
IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities HTML / XSS Injection observed
Published 2026-06-22 · Analyzed
5.4EPSS 0.002
CVE-2020-4544
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 183189.
Published 2021-01-08 · Modified
4.3EPSS 0.010
CVE-2020-4487
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181862.
Published 2021-01-08 · Modified
4.3EPSS 0.010
CVE-2021-29701
IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 as well as IBM Rational Team Concert 6.0.6 and 6.0.6.1 could allow an authneticated attacker to obtain sensitive information from build definitions that could aid in further attacks against the system. IBM X-Force ID: 200657.
Published 2022-01-11 · Modified
4.3EPSS 0.007
CVE-2020-4964
IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users. IBM X-Force ID: 192419.
Published 2021-04-12 · Modified
4.3EPSS 0.006
← Prev2 / 2