CVE-2021-20502

IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 198059.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
ibmCNA
7.1 HIGH
NETWORK
LOW
LOW
CVSS:3.0/I:N/C:H/UI:N/AV:N/AC:L/A:L/S:U/PR:L/RC:C/RL:O/E:U
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
VendorProductVersion
ibmengineering_insights
7.0
ibmengineering_insights
7.0.1
ibmengineering_insights
7.0.2
ibmengineering_lifecycle_management
7.0
ibmengineering_requirements_quality_assistant_on-premises
-
ibmengineering_workflow_management
7.0.0
ibmengineering_workflow_management
7.0.1
ibmengineering_workflow_management
7.0.2
ibmrational_engineering_lifecycle_manager
6.0.2
ibmrational_engineering_lifecycle_manager
6.0.6
ibmrational_engineering_lifecycle_manager
6.0.6.1
ibmrational_team_concert
6.0.6
ibmrational_team_concert
6.0.6.1
ibmrational_team_concert
6.0.6.2
𝑥
= Vulnerable software versions