Cross-Site Scripting Vulnerability in IBM Jazz Foundation Products
CVE-2021-20504

5.4MEDIUM

Summary

IBM Jazz Foundation Products exhibit a cross-site scripting vulnerability that permits users to inject arbitrary JavaScript into the web interface. This security flaw can compromise the application’s intended functionalities and may lead to unintended credential disclosure during a trusted session. Organizations using these products must evaluate their exposure and implement appropriate security measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

Engineering Lifecycle Optimization 7.0

Engineering Lifecycle Optimization 7.0.1

Engineering Lifecycle Optimization 7.0.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.