Engineering Lifecycle Optimization Publishing
engineering_lifecycle_optimization_-_publishing
Vendor: Ibm • 28 CVEs
CVEs (28)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 2Engineering Lifecycle Optimization Publishing Engineering Lifecycle Optimization PublishingJun 17, 2026 Jul 14, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker t...Show more |
1Ibm 2Engineering Lifecycle Optimization Publishing Engineering Lifecycle Optimization PublishingJun 17, 2026 Jul 14, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitive information through an HTTP GET request to an authenticated user. IBM X-Force ID: 213728. |
1Ibm 2Engineering Lifecycle Optimization Publishing Engineering Lifecycle Optimization PublishingJun 17, 2026 Jul 14, 2022 N/A· v4 4.3 MEDIUM· v3 N/A· v2 IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose sensitive information in a SQL error message that could aid in further attacks against the system. IBM X-Force ID:...Show more |
1Ibm 2Engineering Lifecycle Optimization Publishing Engineering Lifecycle Optimization PublishingJun 17, 2026 Jul 14, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 213725. |
1Ibm 2Engineering Lifecycle Optimization Publishing Engineering Lifecycle Optimization PublishingJun 17, 2026 Jul 14, 2022 N/A· v4 4.3 MEDIUM· v3 N/A· v2 IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 does not sufficiently monitor or control transmitted network traffic volume, so that an actor can cause the software to transmit m...Show more |
1Ibm 2Engineering Lifecycle Optimization Publishing Engineering Lifecycle Optimization PublishingJun 17, 2026 Jul 14, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 IBM Engineering Lifecycle Optimization - Publishing 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more |
1Ibm 9Collaborative Lifecycle Management Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 moreJun 17, 2026 Jun 2, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential...Show more |
1Ibm 9Collaborative Lifecycle Management Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 moreJun 17, 2026 Jun 2, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential...Show more |
1Ibm 9Collaborative Lifecycle Management Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 moreJun 17, 2026 Jun 2, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information could be used in further attacks against t...Show more |
1Ibm 9Collaborative Lifecycle Management Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 moreJun 17, 2026 Jun 2, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to networ...Show more |
1Ibm 9Collaborative Lifecycle Management Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 moreJun 17, 2026 Jun 2, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to networ...Show more |
1Ibm 9Collaborative Lifecycle Management Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 moreJun 17, 2026 Jun 2, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to networ...Show more |
1Ibm 9Collaborative Lifecycle Management Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 moreJun 17, 2026 Jun 2, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to networ...Show more |
1Ibm 9Collaborative Lifecycle Management Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 moreJun 17, 2026 Jun 2, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to networ...Show more |
1Ibm 9Collaborative Lifecycle Management Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 moreJun 17, 2026 Jun 2, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential...Show more |
1Ibm 9Collaborative Lifecycle Management Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 moreJun 17, 2026 Jun 2, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential...Show more |
1Ibm 9Collaborative Lifecycle Management Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 moreJun 17, 2026 Jun 2, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality...Show more |
1Ibm 9Collaborative Lifecycle Management Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 moreJun 17, 2026 Jun 2, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126. |
1Ibm 9Collaborative Lifecycle Management Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 moreJun 17, 2026 Jun 2, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could...Show more |
1Ibm 1Engineering Lifecycle Optimization Publishing Jun 17, 2026 Jul 16, 2020 N/A· v4 4.7 MEDIUM· v3 4.3 MEDIUM· v2 IBM Publishing Engine 6.0.6, 6.0.6.1, and 7.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by plantin...Show more |