First published: Mon Oct 25 2021(Updated: )
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM CLM | <=6.0.6.1 | |
IBM CLM | <=6.0.6 | |
IBM ELM | <=7.0.2 | |
IBM ELM | <=7.0 | |
IBM ELM | <=7.0.1 | |
IBM Engineering Requirements Quality Assistant | <=1.0 | |
IBM Engineering Requirements Quality Assistant On-Premises | <=All | |
IBM EWM | <=7.0.2 | |
IBM EWM | <=7.0.1 | |
IBM RTC | <=6.0.2 | |
IBM RTC | <=6.0.6.1 | |
IBM EWM | <=7.0 | |
IBM RTC | <=6.0.6 | |
IBM Engineering Systems Design Rhapsody | <=All | |
IBM DOORS Next | <=7.0.2 | |
IBM DOORS Next | <=7.0 | |
IBM DOORS Next | <=7.0.1 | |
IBM RDNG | <=6.0.6.1 | |
IBM RDNG | <=6.0.6 | |
IBM Engineering Lifecycle Optimization | =7.0 | |
IBM Engineering Lifecycle Optimization | =7.0.1 | |
IBM Engineering Lifecycle Optimization | =7.0.2 | |
IBM Rational Collaborative Lifecycle Management | =6.0.6 | |
IBM Rational Collaborative Lifecycle Management | =6.0.6.1 | |
IBM Rational Collaborative Lifecycle Management | =7.0.1 | |
IBM Rational Collaborative Lifecycle Management | =7.0.2 | |
IBM Rational DOORS Next Generation | =6.0.2 | |
IBM Rational DOORS Next Generation | =6.0.6 | |
IBM Rational DOORS Next Generation | =6.0.6.1 | |
IBM Rational Engineering Lifecycle Manager | =6.0.6 | |
IBM Rational Engineering Lifecycle Manager | =6.0.6.1 | |
IBM Rational Engineering Lifecycle Manager | =7.0 | |
IBM Rational Engineering Lifecycle Manager | =7.0.1 | |
IBM Rational Engineering Lifecycle Manager | =7.0.2 | |
IBM Rational Team Concert | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-29713 is medium with a severity value of 5.4.
IBM Jazz Team Server products, including IBM CLM, IBM ELM, IBM Engineering Requirements Quality Assistant, IBM Engineering Requirements Quality Assistant On-Premises, IBM EWM, IBM RTC, IBM Engineering Systems Design Rhapsody, IBM DOORS Next, and IBM RDNG are affected by CVE-2021-29713.
CVE-2021-29713 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
The Common Weakness Enumeration (CWE) ID of CVE-2021-29713 is CWE-79.
You can find more information about CVE-2021-29713 at the following references: [IBM X-Force Exchange](https://exchange.xforce.ibmcloud.com/vulnerabilities/200967) and [IBM Support](https://www.ibm.com/support/pages/node/6508583).