Lucene search

K
nvd[email protected]NVD:CVE-2021-20421
HistoryJun 24, 2022 - 5:15 p.m.

CVE-2021-20421

2022-06-2417:15:07
CWE-918
web.nvd.nist.gov
2
ibm jazz team server
ssrf vulnerability
network enumeration

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

19.6%

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

Affected configurations

Nvd
Node
ibmjazz_team_serverMatch6.0.6
OR
ibmjazz_team_serverMatch6.0.6.1
OR
ibmjazz_team_serverMatch7.0
OR
ibmjazz_team_serverMatch7.0.1
OR
ibmjazz_team_serverMatch7.0.2
AND
linuxlinux_kernelMatch-
OR
microsoftwindowsMatch-
VendorProductVersionCPE
ibmjazz_team_server6.0.6cpe:2.3:a:ibm:jazz_team_server:6.0.6:*:*:*:*:*:*:*
ibmjazz_team_server6.0.6.1cpe:2.3:a:ibm:jazz_team_server:6.0.6.1:*:*:*:*:*:*:*
ibmjazz_team_server7.0cpe:2.3:a:ibm:jazz_team_server:7.0:*:*:*:*:*:*:*
ibmjazz_team_server7.0.1cpe:2.3:a:ibm:jazz_team_server:7.0.1:*:*:*:*:*:*:*
ibmjazz_team_server7.0.2cpe:2.3:a:ibm:jazz_team_server:7.0.2:*:*:*:*:*:*:*
linuxlinux_kernel-cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

19.6%

Related for NVD:CVE-2021-20421