IBM Jazz for Service Management是美国国际商业机器(IBM)公司的一款提供对服务管理环境可见性的集成服务管理产品。 IBM Jazz for Service Management存在跨站脚本漏洞,该漏洞源于跨站点脚本攻击。此漏洞允许未经身份验证的攻击者在Web UI中嵌入任意JavaScript代码,从而改变预期功能,可能导致受信任会话中的凭据泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Jazz for Service Management | 1.1.3 ~ 1.1.3.23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-51450 | 9.1 CRITICAL | IBM Security Verify Directory Command Execution |
| CVE-2024-49814 | 7.8 HIGH | IBM Security Verify Access Appliance Privilege Escalation |
| CVE-2024-54171 | 7.1 HIGH | IBM EntireX XML external entity injection |
| CVE-2025-0799 | 6.5 MEDIUM | IBM App Connect Enterprise Arbitrary File Write |
| CVE-2025-0158 | 5.5 MEDIUM | IBM EntireX denial of service |
| CVE-2024-56467 | 3.3 LOW | IBM EntireX information disclosure |
No comments yet