VendorsIBMjazz_foundationall versions
Vulnerabilities

IBM Jazz Foundation

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2025-36157
IBM Engineering Lifecycle Management incorrect authorization
Published 2025-08-24 · Analyzed
9.8EPSS 0.005
CVE-2019-4457
IBM Jazz Foundation 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 could allow an authenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 163654.
Published 2020-02-19 · Modified
6.5EPSS 0.009
CVE-2025-25048
IBM Jazz Foundation path traversal
Published 2025-09-04 · Analyzed
6.5EPSS 0.003
CVE-2023-45181
IBM Jazz Foundation cross-site scripting
Published 2024-11-25 · Analyzed
6.1EPSS 0.003
CVE-2024-43184
IBM Jazz Foundation cross-site scripting
Published 2025-09-04 · Analyzed
6.1EPSS 0.002
CVE-2021-39059
IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214619.
Published 2022-05-11 · Modified
5.4EPSS 0.005
CVE-2021-29669
IBM Jazz Foundation cross-site scripting
Published 2025-01-12 · Analyzed
5.4EPSS 0.002
CVE-2025-15395
IBM Jazz Foundation access control violation
Published 2026-02-02 · Analyzed
5.4EPSS 0.002
CVE-2025-1826
IBM Jazz Foundation cross-site scripting
Published 2025-10-07 · Analyzed
5.4EPSS 0.002
CVE-2023-26280
IBM Jazz Foundation improper access control
Published 2024-11-25 · Analyzed
5.3EPSS 0.004
CVE-2024-41780
IBM Jazz Foundation information disclosure
Published 2025-01-03 · Analyzed
4.6EPSS 0.002
CVE-2024-5591
IBM Jazz Foundation information disclosure
Published 2025-01-03 · Analyzed
4.3EPSS 0.004