CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

ibm

engineering_lifecycle_management

45 known vulnerabilities · sorted by CVSS score

CVE-2020-4495
HIGH8.8

IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions, and execute arbitrary actions with administrative privileges. IBM X-Force ID: 182114.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021
Page 1 of 3
CVE-2020-4965
HIGH7.5

IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192422.

ibm / collaborative_lifecycle_management+37
Network
Published Apr 12, 2021
CVE-2021-20502
HIGH7.1

IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 198059.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2020-4732
MEDIUM6.5

IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021
CVE-2021-20371
MEDIUM6.5

IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195516.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021
CVE-2025-36033
MEDIUM5.4

IBM Engineering Lifecycle Management - Global Configuration Management 7.0.3 through 7.0.3 Interim Fix 017, and 7.1.0 through 7.1.0 Interim Fix 004 IBM Global Configuration Management is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

ibm / engineering_lifecycle_management+22
Network
Published Feb 3, 2026
CVE-2021-20351
MEDIUM5.4

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194708.

ibm / doors_next+22
Network
Published Mar 4, 2021
CVE-2021-20357
MEDIUM5.4

IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194963.

ibm / collaborative_lifecycle_management+29
Network
Published Jan 27, 2021
CVE-2020-4920
MEDIUM5.4

IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191396.

ibm / collaborative_lifecycle_management+37
Network
Published Apr 12, 2021
CVE-2020-4856
MEDIUM5.4

IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190459.

ibm / doors_next+22
Network
Published Mar 4, 2021
CVE-2021-20346
MEDIUM5.4

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194595.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021
CVE-2021-20504
MEDIUM5.4

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198231.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2021-20519
MEDIUM5.4

IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198441.

ibm / collaborative_lifecycle_management+37
Network
Published Apr 12, 2021
CVE-2020-4697
MEDIUM5.4

IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186790.

ibm / collaborative_lifecycle_management+32
Network
Published Jan 8, 2021
CVE-2020-4733
MEDIUM5.4

IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188127.

ibm / collaborative_lifecycle_management+32
Network
Published Jan 8, 2021
CVE-2020-4865
MEDIUM5.4

IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741.

ibm / collaborative_lifecycle_management+29
Network
Published Jan 27, 2021
CVE-2020-4547
MEDIUM5.4

IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 183315.

ibm / collaborative_lifecycle_management+29
Network
Published Jan 27, 2021
CVE-2021-20352
MEDIUM5.4

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194710.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2020-5030
MEDIUM5.4

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193737.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021
CVE-2021-29670
MEDIUM5.4

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199408.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021