CVE-2021-20343: SSRF
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194593.
Other sources
IBM Jazz Foundation is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is IBM Jazz Foundation vulnerability?
IBM Jazz Foundation is vulnerable to server-side request forgery (SSRF).
What can an attacker do with the vulnerability?
An authenticated attacker can send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
What is the severity of CVE-2021-20343?
The severity of CVE-2021-20343 is medium (5.4).
Which IBM products are affected by CVE-2021-20343?
IBM Collaborative Lifecycle Management, IBM Engineering Lifecycle Management, IBM Engineering Lifecycle Optimization - Engineering Insights, IBM Engineering Lifecycle Optimization - Publishing, IBM Engineering Test Management, IBM Rational DOORS Next Generation, IBM Rational Engineering Lifecycle Manager, IBM Rational Quality Manager, IBM RDNG, IBM Removable Media Manager, IBM Pub, IBM RQM, IBM ETM, IBM CLM, IBM ELM, IBM RMM, IBM RELM, IBM ENI are affected by CVE-2021-20343.
How can I fix the vulnerability in IBM Jazz Foundation?
Ensure that you have the latest patches and updates installed for the affected IBM products, as provided by IBM.