Aller au contenu

Fiche vulnérabilité

CVE-2021-29844 : faille moyenne IBM Engineering Workflow Management (CVSS 5.4)

Description

IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

En bref

Sévérité
Moyenne (CVSS 5.4)
Vecteur CVSS
CVSS:3.0/I:L/C:L/S:U/PR:L/AV:N/A:N/UI:N/AC:L/RC:C/E:U/RL:O
Exploitation active
Non signalée par la CISA
Publication
27 oct. 2021
Dernière mise à jour
16 sept. 2024

Produits concernés

  • IBM Engineering Workflow Management
  • IBM Rational DOORS Next Generation
  • IBM Rational Team Concert
  • IBM Rational Engineering Lifecycle Manager
  • IBM Engineering Lifecycle Optimization
  • IBM Rational Collaborative Lifecycle Management

Références

Rechercher une autre vulnérabilité dans la base CVE