CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

ibm

engineering_insights

22 known vulnerabilities · sorted by CVSS score

CVE-2020-4965
HIGH7.5

IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192422.

ibm / collaborative_lifecycle_management+37
Network
Published Apr 12, 2021
Page 1 of 2
CVE-2021-20502
HIGH7.1

IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 198059.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2020-4547
MEDIUM5.4

IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 183315.

ibm / collaborative_lifecycle_management+29
Network
Published Jan 27, 2021
CVE-2020-4920
MEDIUM5.4

IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191396.

ibm / collaborative_lifecycle_management+37
Network
Published Apr 12, 2021
CVE-2021-20504
MEDIUM5.4

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198231.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2021-20519
MEDIUM5.4

IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198441.

ibm / collaborative_lifecycle_management+37
Network
Published Apr 12, 2021
CVE-2020-4697
MEDIUM5.4

IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186790.

ibm / collaborative_lifecycle_management+32
Network
Published Jan 8, 2021
CVE-2020-4865
MEDIUM5.4

IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741.

ibm / collaborative_lifecycle_management+29
Network
Published Jan 27, 2021
CVE-2021-20352
MEDIUM5.4

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194710.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2020-4524
MEDIUM5.4

IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182434.

ibm / collaborative_lifecycle_management+29
Network
Published Jan 27, 2021
CVE-2021-20357
MEDIUM5.4

IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194963.

ibm / collaborative_lifecycle_management+29
Network
Published Jan 27, 2021
CVE-2020-4733
MEDIUM5.4

IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188127.

ibm / collaborative_lifecycle_management+32
Network
Published Jan 8, 2021
CVE-2020-4691
MEDIUM5.4

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186698.

ibm / collaborative_lifecycle_management+32
Network
Published Jan 8, 2021
CVE-2021-20520
MEDIUM5.4

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198572.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2021-20447
MEDIUM5.4

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196623.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2021-20518
MEDIUM5.4

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198437.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2021-20506
MEDIUM5.4

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198231.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2021-20503
MEDIUM5.4

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198182.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2020-4855
MEDIUM5.4

IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190457.

ibm / collaborative_lifecycle_management+29
Network
Published Jan 27, 2021
CVE-2020-4964
MEDIUM4.3

IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users. IBM X-Force ID: 192419.

ibm / collaborative_lifecycle_management+37
Network
Published Apr 12, 2021