CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

ibm

engineering_requirements_quality_assistant_on-premises

29 known vulnerabilities · sorted by CVSS score

CVE-2021-29844
HIGH8.8

IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

ibm / engineering_lifecycle_optimization+18
Network
Published Oct 27, 2021
Page 1 of 2
CVE-2021-20502
HIGH7.1

IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 198059.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2021-29899
MEDIUM6.5

IBM Engineering Requirements Quality Assistant prior to 3.1.3 could allow an authenticated user to cause a denial of service. IBM X-Force ID: 207413.

ibm / engineering_requirements_quality_assistant_on-premises
Network
Published Mar 18, 2022
CVE-2021-29799
MEDIUM6.5

IBM Engineering Requirements Quality Assistant On-Premises (All versions) could allow an authenticated user to obtain sensitive information due to improper client side validation. IBM X-Force ID: 203738.

ibm / engineering_requirements_quality_assistant_on-premises
Network
Published Jul 18, 2022
CVE-2021-38868
MEDIUM6.5

IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force Id: 208310.

ibm / engineering_requirements_quality_assistant_on-premises
Network
Published Jul 18, 2022
CVE-2020-4974
MEDIUM6.3

IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 192434.

ibm / engineering_lifecycle_optimization_-_engineering_insights+24
Network
Published Jul 28, 2021
CVE-2021-20352
MEDIUM5.4

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194710.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2020-4663
MEDIUM5.4

IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186234.

ibm / engineering_requirements_quality_assistant_on-premises
Network
Published Jan 8, 2021
CVE-2020-4866
MEDIUM5.4

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190742.

ibm / doors_next+22
Network
Published Mar 4, 2021
CVE-2021-20340
MEDIUM5.4

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194451.

ibm / doors_next+22
Network
Published Mar 4, 2021
CVE-2020-4975
MEDIUM5.4

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192435.

ibm / doors_next+22
Network
Published Mar 4, 2021
CVE-2021-29790
MEDIUM5.4

IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 203440.

ibm / engineering_requirements_quality_assistant_on-premises
Network
Published Jul 18, 2022
CVE-2021-20518
MEDIUM5.4

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198437.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2021-20506
MEDIUM5.4

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198231.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2021-20503
MEDIUM5.4

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198182.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2020-4863
MEDIUM5.4

IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190566.

ibm / doors_next+22
Network
Published Mar 4, 2021
CVE-2021-20350
MEDIUM5.4

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194707.

ibm / doors_next+22
Network
Published Mar 4, 2021
CVE-2021-29788
MEDIUM5.4

IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 203310.

ibm / engineering_requirements_quality_assistant_on-premises
Network
Published Jul 18, 2022
CVE-2021-20447
MEDIUM5.4

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196623.

ibm / engineering_insights+13
Network
Published Mar 30, 2021
CVE-2021-20507
MEDIUM5.4

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198235.

ibm / engineering_lifecycle_optimization+16
Network
Published Jul 19, 2021