CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

ibm

engineering_lifecycle_optimization_-_publishing

26 known vulnerabilities · sorted by CVSS score

CVE-2020-4495
HIGH8.8

IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions, and execute arbitrary actions with administrative privileges. IBM X-Force ID: 182114.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021
Page 1 of 2
CVE-2020-4732
MEDIUM6.5

IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021
CVE-2021-39017
MEDIUM6.5

IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 213725.

ibm / engineering_lifecycle_optimization_-_publishing+4
Network
Published Jul 14, 2022
CVE-2021-20371
MEDIUM6.5

IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195516.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021
CVE-2021-39019
MEDIUM6.5

IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitive information through an HTTP GET request to an authenticated user. IBM X-Force ID: 213728.

ibm / engineering_lifecycle_optimization_-_publishing+4
Network
Published Jul 14, 2022
CVE-2019-4431
MEDIUM5.4

IBM Rational Publishing Engine 6.0.6 and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162888.

ibm / engineering_lifecycle_optimization_-_publishing+1
Network
Published Feb 12, 2020
CVE-2021-29668
MEDIUM5.4

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199406.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021
CVE-2018-1951
MEDIUM5.4

IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153494.

ibm / engineering_lifecycle_optimization_-_publishing+2
Network
Published Jan 4, 2019
CVE-2020-4977
MEDIUM5.4

IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192470.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021
CVE-2018-1657
MEDIUM5.4

IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 144883.

ibm / engineering_lifecycle_optimization_-_publishing+2
Network
Published Jan 4, 2019
CVE-2021-29670
MEDIUM5.4

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199408.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021
CVE-2021-20346
MEDIUM5.4

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194595.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021
CVE-2018-1534
MEDIUM5.4

IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142432.

ibm / engineering_lifecycle_optimization_-_publishing+1
Network
Published Oct 12, 2018
CVE-2021-39015
MEDIUM5.4

IBM Engineering Lifecycle Optimization - Publishing 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213655.

ibm / engineering_lifecycle_optimization_-_publishing+4
Network
Published Jul 14, 2022
CVE-2020-5030
MEDIUM5.4

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193737.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021
CVE-2018-1533
MEDIUM5.4

IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142431.

ibm / engineering_lifecycle_optimization_-_publishing+1
Network
Published Oct 12, 2018
CVE-2021-20345
MEDIUM5.4

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194594.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021
CVE-2021-20347
MEDIUM5.4

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194596.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021
CVE-2021-20348
MEDIUM5.4

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-ForceID: 194597.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021
CVE-2021-20338
MEDIUM5.4

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194449.

ibm / collaborative_lifecycle_management+24
Network
Published Jun 2, 2021