← Vulnerability feed

Vulnerability record · CVE-2024-52890 · published 5 August 2025

CVE-2024-52890: Ibm engineering lifecycle optimization vulnerability

Ibm · Engineering Lifecycle Optimization

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs.

6.1 CVSS 3.1 Medium EPSS 0.18% · top 92.9% CWE-84 · CWE-84
6.1CVSS 3.1 base score
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-52890 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-45187Ibm engineering lifecycle optimization insufficient session expiration vulnerabilityIBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated user …EPSS 0.38%8.8CVE-2021-29844Ibm engineering lifecycle optimization server-side request forgery (ssrf) vulnerabilityIBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ…EPSS 0.59%7.5CVE-2023-45191Ibm engineering lifecycle optimization improper restriction of authentication attempts vulnerabilityIBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force a…EPSS 0.66%7.5CVE-2021-29774Ibm engineering lifecycle optimization vulnerabilityIBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.EPSS 0.98%6.5CVE-2021-29786Ibm engineering lifecycle optimization cleartext storage of sensitive data vulnerabilityIBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.EPSS 0.56%6.1CVE-2023-45190Ibm engineering lifecycle optimization improper restriction of authentication attempts vulnerabilityIBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST hea…EPSS 0.26%5.4CVE-2021-29673Ibm engineering lifecycle optimization cross-site scripting vulnerabilityIBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…EPSS 0.50%5.4CVE-2021-29713Ibm engineering lifecycle optimization cross-site scripting vulnerabilityIBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…EPSS 0.50%

Source: NIST National Vulnerability Database (record CVE-2024-52890), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.