First published: Mon May 31 2021(Updated: )
IBM Engineering Lifecycle Optimization - Engineering Insights is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Collaborative Lifecycle Management | =6.0.6 | |
IBM Collaborative Lifecycle Management | =6.0.6.1 | |
IBM Engineering Lifecycle Manager | =7.0 | |
IBM Engineering Lifecycle Manager | =7.0.1 | |
IBM Engineering Lifecycle Manager | =7.0.2 | |
IBM Engineering Insights | =7.0 | |
IBM Engineering Insights | =7.0.1 | |
IBM Engineering Insights | =7.0.2 | |
IBM Engineering Lifecycle Optimization | =7.0 | |
IBM Engineering Lifecycle Optimization | =7.0.1 | |
IBM Engineering Lifecycle Optimization | =7.0.2 | |
IBM Engineering Test Management (ETM) | =7.0.0 | |
IBM Engineering Test Management (ETM) | =7.0.1 | |
IBM Rational DOORS | =6.0.6 | |
IBM Rational DOORS | =6.0.6.1 | |
IBM Rational DOORS | =7.0 | |
IBM Rational DOORS | =7.0.1 | |
IBM Rational DOORS | =7.0.2 | |
IBM Engineering Lifecycle Manager | =6.0.6 | |
IBM Engineering Lifecycle Manager | =6.0.6.1 | |
IBM Rational Quality Manager | =6.0.6 | |
IBM Rational Quality Manager | =6.0.6.1 | |
IBM Removable Media Management | =6.0.6 | |
IBM Removable Media Management | =6.0.6.1 | |
IBM Removable Media Management | =7.0 | |
IBM Rational DOORS Next Generation | <=7.0.2 | |
IBM Rational DOORS Next Generation | <=7.0 | |
IBM Rational DOORS Next Generation | <=7.0.1 | |
IBM Rational DOORS Next Generation | <=6.0.6.1 | |
IBM Rational DOORS Next Generation | <=6.0.6 | |
IBM Pub | <=7.0.1 | |
IBM Pub | <=7.0.2 | |
IBM Pub | <=7.0 | |
IBM Rational Quality Manager (RQM) | <=6.0.6.1 | |
IBM Engineering Test Management (ETM) | <=7.0.1 | |
IBM Rational Quality Manager (RQM) | <=6.0.6 | |
IBM Engineering Test Management (ETM) | <=7.0.0 | |
IBM Engineering Lifecycle Management | <=6.0.6.1 | |
IBM Engineering Lifecycle Management | <=6.0.6 | |
IBM Engineering Lifecycle Management (ELM) | <=7.0.2 | |
IBM Engineering Lifecycle Management (ELM) | <=7.0 | |
IBM Engineering Lifecycle Management (ELM) | <=7.0.1 | |
IBM Removable Media Manager | <=6.0.6.1 | |
IBM Removable Media Manager | <=6.0.6 | |
IBM Removable Media Manager | <=7.0 | |
IBM Engineering Lifecycle Management (ELM) | <=6.0.6.1 | |
IBM ENI | <=7.0.1 | |
IBM Engineering Lifecycle Management (ELM) | <=6.0.6 | |
IBM ENI | <=7.0 | |
IBM ENI | <=7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-29670.
The severity of CVE-2021-29670 is medium with a score of 5.4.
The following IBM products are affected by CVE-2021-29670: IBM DOORS Next 7.0.2, IBM DOORS Next 7.0, IBM DOORS Next 7.0.1, IBM RDNG 6.0.6.1, IBM RDNG 6.0.6, IBM Pub 7.0.1, IBM Pub 7.0.2, IBM Pub 7.0, IBM RQM 6.0.6.1, IBM ETM 7.0.1, IBM RQM 6.0.6, IBM ETM 7.0.0, IBM CLM 6.0.6.1, IBM CLM 6.0.6, IBM ELM 7.0.2, IBM ELM 7.0, IBM ELM 7.0.1, IBM RMM 6.0.6.1, IBM RMM 6.0.6, IBM RMM 7.0, IBM RELM 6.0.6.1, IBM ENI 7.0.1, IBM RELM 6.0.6, IBM ENI 7.0, IBM ENI 7.0.2.
CVE-2021-29670 is a vulnerability in IBM Jazz Foundation and IBM Engineering products that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
IBM has not released a patch for CVE-2021-29670 yet. It is recommended to follow the security advisory provided by IBM and apply any necessary updates or mitigations as they become available.