|
194621
|
7.5 |
HIGH
Network
|
ibm
|
rational_team_concert rational_doors_next_generation rational_engineering_lifecycle_manager engineering_workflow_management rational_collaborative_lifecycle_management engineering_life…
|
IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.
|
NVD-CWE-noinfo
|
CVE-2021-29774
|
2024-11-21 15:01 |
2021-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194622
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_doors_next_generation rational_engineering_lifecycle_manager rational_collaborative_lifecycle_management engineering_lifecycle_optimization rational_team_concert
|
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potenti…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29713
|
2024-11-21 15:01 |
2021-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194623
|
8.8 |
HIGH
Network
|
ibm
|
rational_team_concert rational_doors_next_generation rational_engineering_lifecycle_manager engineering_workflow_management engineering_requirements_quality_assistant_on-premises engin…
|
IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to netwo…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-29844
|
2024-11-21 15:01 |
2021-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194624
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_team_concert rational_collaborative_lifecycle_management rational_engineering_lifecycle_manager engineering_workflow_management rational_doors_next_generation engineering_life…
|
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potenti…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29673
|
2024-11-21 15:01 |
2021-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194625
|
6.1 |
MEDIUM
Network
|
ibm
|
business_automation_workflow
|
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the i…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29835
|
2024-11-21 15:01 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194626
|
4.3 |
MEDIUM
Network
|
ibm
|
transformation_extender_advanced
|
IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cook…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2021-29883
|
2024-11-21 15:01 |
2021-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194627
|
8.1 |
HIGH
Network
|
ibm
|
storwize_v5000_software storwize_v7000_software storwize_v3700_software storwize_v3500_software san_volume_controller_firmware spectrum_virtualize spectrum_virtualize_for_public_clo…
|
IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229.
|
NVD-CWE-noinfo
|
CVE-2021-29873
|
2024-11-21 15:01 |
2021-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194628
|
5.4 |
MEDIUM
Network
|
ibm
|
security_risk_manager_on_cp4s
|
IBM Security Risk Manager on CP4S 1.7.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functional…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29912
|
2024-11-21 15:01 |
2021-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194629
|
5.4 |
MEDIUM
Network
|
ibm
|
business_automation_workflow
|
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the i…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29878
|
2024-11-21 15:01 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194630
|
8.8 |
HIGH
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to which they should not have access to. IBM X-Force ID: …
|
NVD-CWE-noinfo
|
CVE-2021-29745
|
2024-11-21 15:01 |
2021-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|