Skip to main content

Vendor/product archive

ibm / jazz_foundation CVEs

Beta · best-effort

12 CVEs tagged to ibm / jazz_foundation1 Critical, 0 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2025-15395

Published Feb 2, 2026

IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violations that allows the users to view or access/perform actions…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1826

Published Oct 7, 2025

IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034, 7.0.3 to 7.0.3 iFix016, and 7.1.0 to 7.1.0 iFix004) is vulnerable to stored cross-s…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25048

Published Sep 4, 2025

IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allow an authenticated user to upload files to the system due t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43184

Published Sep 4, 2025

IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 is vulnerable to cross-site scripting. This vulnerability allows an u…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36157

Published Aug 24, 2025

IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to update server property files that…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-45181

Published Nov 25, 2024

IBM Jazz Foundation 7.0.2 and below are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inte…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26280

Published Nov 25, 2024

IBM Jazz Foundation 7.0.2 and 7.0.3 could allow a user to change their dashboard using a specially crafted HTTP request due to improper access control.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39059

Published May 11, 2022

IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4457

Published Feb 19, 2020

IBM Jazz Foundation 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 could allow an authenticated user to obtain sensitive information that could be used in further atta…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1