Engineering Workflow Management

Vendor:

First CVE: Jul 16, 2020 · Active for 6 years

48
Total CVEs
More Total CVEs than 97% of tracked products
9.6
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Engineering Workflow Management over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 16, 2020
6 years ago
Most Recent CVE
Jun 22, 2026
34 days ago

CVE Severity & Scoring

Engineering Workflow Management48 CVEs
All CVEs352,719 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network48 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low47 (97.9%)
High1 (2.1%)
Unknown0 (0.0%)
User Interaction
None11 (22.9%)
Unknown0 (0.0%)
Required37 (77.1%)
Privileges Required
Low46 (95.8%)
High0 (0.0%)
None2 (4.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (48 CVEs).

48 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is vulnerable to HTTP header injec
Jun 22, 20266.526NONO
IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potential
Oct 27, 20218.826NONO
IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an aut
Jun 22, 20265.425NONO
IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.
Oct 27, 20217.524NONO
IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose
Mar 30, 20217.123NONO
IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.
Oct 27, 20216.522NONO
IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potential
Jul 28, 20216.322NONO
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alter
Jul 19, 20215.421NONO
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fun
Jul 28, 20215.420NONO
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fun
Mar 30, 20215.420NONO

Exploit Exposure

Signals from CVEs in this product scope (48 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (48 CVEs).

Media Mentions

Signals from CVEs in this product scope (48 CVEs).

Top CNAs Publishing CVEs For Engineering Workflow Management

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.1.025.90.2%00
7.0.335.90.2%00
7.0.2366.10.4%00
7.0.1375.60.6%00
7.0.0185.50.6%00
7.0265.60.6%00
6.0.6.165.80.7%00
6.0.665.80.7%00
6.0.255.40.7%00