PublicCVE

CVE-2021-20346

MEDIUM5.4JSON exportCreate alert

Description

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194595.

CVSS breakdown

CVSS 3.0
Confidentiality
Low
Scope
Unchanged
User Interaction
None
Availability
None
Attack Complexity
Low
Integrity
Low
Attack Vector
Network
Privileges Required
Low
RC
Changed
RL
O
E
Unchanged