First published: Mon May 09 2022(Updated: )
IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214619.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz Foundation | =6.0.6 | |
IBM Jazz Foundation | =6.0.6.1 | |
IBM Jazz Foundation | =7.0 | |
IBM Jazz Foundation | =7.0.1 | |
IBM Jazz Foundation | =7.0.2 | |
IBM Jazz Team Server | <=6.0.6, 6.0.6.1, 7.0, 7.0.1, 7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39059 has a severity rating that indicates a significant risk related to cross-site scripting exploitation.
To fix CVE-2021-39059, apply the security patches provided by IBM for affected versions of the Jazz Foundation and Jazz Team Server.
The affected versions of CVE-2021-39059 include IBM Jazz Foundation versions 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2.
CVE-2021-39059 represents a cross-site scripting vulnerability that allows arbitrary JavaScript code to be embedded in the Web UI.
Users of the IBM Jazz Foundation or Jazz Team Server are at risk if they use the specified vulnerable versions.