IBM Jazz Foundation 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
History

Thu, 13 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:ibm:jazz_foundation:7.0:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
Microsoft
Microsoft windows

Mon, 13 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 12 Jan 2025 01:45:00 +0000

Type Values Removed Values Added
Description IBM Jazz Foundation 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM Jazz Foundation cross-site scripting
First Time appeared Ibm
Ibm jazz Foundation
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:jazz_foundation:6.0.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:jazz_foundation:6.0.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:jazz_foundation:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:jazz_foundation:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:jazz_foundation:7.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm jazz Foundation
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-01-12T01:30:05.836Z

Updated: 2025-01-13T15:18:46.605Z

Reserved: 2021-03-31T20:12:10.358Z

Link: CVE-2021-29669

cve-icon Vulnrichment

Updated: 2025-01-13T15:18:39.900Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-12T02:15:18.750

Modified: 2025-03-13T16:25:10.947

Link: CVE-2021-29669

cve-icon Redhat

No data.