CVE-2021-20347: SSRF
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194596.
Other sources
IBM Jazz Foundation is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM Jazz Foundation vulnerability?
The vulnerability ID for this IBM Jazz Foundation vulnerability is CVE-2021-20347.
What is the impact of the CVE-2021-20347 vulnerability?
The impact of the CVE-2021-20347 vulnerability is that an authenticated attacker may be able to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
What products are affected by the CVE-2021-20347 vulnerability?
The products affected by the CVE-2021-20347 vulnerability include IBM DOORS Next, IBM RDNG, IBM Pub, IBM RQM, IBM ETM, IBM CLM, IBM ELM, IBM RMM, IBM RELM, IBM ENI, IBM Engineering Lifecycle Management, IBM Engineering Lifecycle Optimization - Engineering Insights, IBM Engineering Lifecycle Optimization - Publishing, IBM Engineering Test Management, IBM Rational DOORS Next Generation, IBM Rational Engineering Lifecycle Manager, IBM Rational Quality Manager, and IBM RDNG Removable Media Manager.
What is the severity of the CVE-2021-20347 vulnerability?
The severity of the CVE-2021-20347 vulnerability is medium with a CVSS score of 5.4.
Where can I find more information about the CVE-2021-20347 vulnerability?
You can find more information about the CVE-2021-20347 vulnerability on the IBM X-Force Exchange website and the IBM Support website.