Description
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198235.
Related CPE's
a
ibm
engineering_lifecycle_optimization
a
ibm
engineering_workflow_management
a
ibm
rational_collaborative_lifecycle_management
a
ibm
rational_doors_next_generation
a
ibm
rational_engineering_lifecycle_manager
a
ibm
rational_team_concert
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
5.4 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Analyzed
Published
2021-07-19T16:15:08.650
3 years agoLast modified
2021-07-26T20:00:56.643
3 years ago