Fiche vulnérabilité
CVE-2021-29844 : faille moyenne IBM Engineering Workflow Management (CVSS 5.4)
Description
IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
En bref
- Sévérité
- Moyenne (CVSS 5.4)
- Vecteur CVSS
- CVSS:3.0/I:L/C:L/S:U/PR:L/AV:N/A:N/UI:N/AC:L/RC:C/E:U/RL:O
- Exploitation active
- Non signalée par la CISA
- Publication
- 27 oct. 2021
- Dernière mise à jour
- 16 sept. 2024
Produits concernés
- IBM Engineering Workflow Management
- IBM Rational DOORS Next Generation
- IBM Rational Team Concert
- IBM Rational Engineering Lifecycle Manager
- IBM Engineering Lifecycle Optimization
- IBM Rational Collaborative Lifecycle Management