CVE-2021-29713: XSS
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-29713?
The severity of CVE-2021-29713 is medium with a severity value of 5.4.
What products are affected by CVE-2021-29713?
IBM Jazz Team Server products, including IBM CLM, IBM ELM, IBM Engineering Requirements Quality Assistant, IBM Engineering Requirements Quality Assistant On-Premises, IBM EWM, IBM RTC, IBM Engineering Systems Design Rhapsody, IBM DOORS Next, and IBM RDNG are affected by CVE-2021-29713.
How does CVE-2021-29713 affect users?
CVE-2021-29713 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
What is the Common Weakness Enumeration (CWE) ID of CVE-2021-29713?
The Common Weakness Enumeration (CWE) ID of CVE-2021-29713 is CWE-79.
Where can I find more information about CVE-2021-29713?
You can find more information about CVE-2021-29713 at the following references: [IBM X-Force Exchange](https://exchange.xforce.ibmcloud.com/vulnerabilities/200967) and [IBM Support](https://www.ibm.com/support/pages/node/6508583).