First published: Mon May 31 2021(Updated: )
IBM Engineering Lifecycle Optimization - Engineering Insights is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Collaborative Lifecycle Management | =6.0.6 | |
Ibm Collaborative Lifecycle Management | =6.0.6.1 | |
IBM Engineering Lifecycle Management | =7.0 | |
IBM Engineering Lifecycle Management | =7.0.1 | |
IBM Engineering Lifecycle Management | =7.0.2 | |
IBM Engineering Lifecycle Optimization - Engineering Insights | =7.0 | |
IBM Engineering Lifecycle Optimization - Engineering Insights | =7.0.1 | |
IBM Engineering Lifecycle Optimization - Engineering Insights | =7.0.2 | |
IBM Engineering Lifecycle Optimization - Publishing | =7.0 | |
IBM Engineering Lifecycle Optimization - Publishing | =7.0.1 | |
IBM Engineering Lifecycle Optimization - Publishing | =7.0.2 | |
IBM Engineering Test Management | =7.0.0 | |
IBM Engineering Test Management | =7.0.1 | |
IBM Rational DOORS Next Generation | =6.0.6 | |
IBM Rational DOORS Next Generation | =6.0.6.1 | |
IBM Rational DOORS Next Generation | =7.0 | |
IBM Rational DOORS Next Generation | =7.0.1 | |
IBM Rational DOORS Next Generation | =7.0.2 | |
IBM Rational Engineering Lifecycle Manager | =6.0.6 | |
IBM Rational Engineering Lifecycle Manager | =6.0.6.1 | |
IBM Rational Quality Manager | =6.0.6 | |
IBM Rational Quality Manager | =6.0.6.1 | |
Ibm Removable Media Manager | =6.0.6 | |
Ibm Removable Media Manager | =6.0.6.1 | |
Ibm Removable Media Manager | =7.0 | |
IBM DOORS Next | <=7.0.2 | |
IBM DOORS Next | <=7.0 | |
IBM DOORS Next | <=7.0.1 | |
IBM RDNG | <=6.0.6.1 | |
IBM RDNG | <=6.0.6 | |
IBM Pub | <=7.0.1 | |
IBM Pub | <=7.0.2 | |
IBM Pub | <=7.0 | |
IBM RQM | <=6.0.6.1 | |
IBM ETM | <=7.0.1 | |
IBM RQM | <=6.0.6 | |
IBM ETM | <=7.0.0 | |
IBM CLM | <=6.0.6.1 | |
IBM CLM | <=6.0.6 | |
IBM ELM | <=7.0.2 | |
IBM ELM | <=7.0 | |
IBM ELM | <=7.0.1 | |
IBM RMM | <=6.0.6.1 | |
IBM RMM | <=6.0.6 | |
IBM RMM | <=7.0 | |
IBM RELM | <=6.0.6.1 | |
IBM ENI | <=7.0.1 | |
IBM RELM | <=6.0.6 | |
IBM ENI | <=7.0 | |
IBM ENI | <=7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-29670.
The severity of CVE-2021-29670 is medium with a score of 5.4.
The following IBM products are affected by CVE-2021-29670: IBM DOORS Next 7.0.2, IBM DOORS Next 7.0, IBM DOORS Next 7.0.1, IBM RDNG 6.0.6.1, IBM RDNG 6.0.6, IBM Pub 7.0.1, IBM Pub 7.0.2, IBM Pub 7.0, IBM RQM 6.0.6.1, IBM ETM 7.0.1, IBM RQM 6.0.6, IBM ETM 7.0.0, IBM CLM 6.0.6.1, IBM CLM 6.0.6, IBM ELM 7.0.2, IBM ELM 7.0, IBM ELM 7.0.1, IBM RMM 6.0.6.1, IBM RMM 6.0.6, IBM RMM 7.0, IBM RELM 6.0.6.1, IBM ENI 7.0.1, IBM RELM 6.0.6, IBM ENI 7.0, IBM ENI 7.0.2.
CVE-2021-29670 is a vulnerability in IBM Jazz Foundation and IBM Engineering products that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
IBM has not released a patch for CVE-2021-29670 yet. It is recommended to follow the security advisory provided by IBM and apply any necessary updates or mitigations as they become available.