
CVE-2018-1394
https://notcve.org/view.php?id=CVE-2018-1394
20 Aug 2018 — Multiple IBM Rational products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138425. Múltiples productos IBM Rational son vulnerables a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidad... • https://exchange.xforce.ibmcloud.com/vulnerabilities/138425 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1729
https://notcve.org/view.php?id=CVE-2017-1729
10 Jul 2018 — IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134909. IBM Rational Quality Manager, desde la versión 5.0 hasta la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los ... • http://www.ibm.com/support/docview.wss?uid=ibm10716607 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1738
https://notcve.org/view.php?id=CVE-2017-1738
10 Jul 2018 — IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 contains an undisclosed vulnerability that would allow an authenticated user to obtain elevated privileges. IBM X-Force ID: 134919. IBM Rational Quality Manager, desde la versión 5.0 hasta la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, contiene una vulnerabilidad sin revelar que permitiría que un usuario autenticado obtenga privilegios elevados. IBM X-Force ID: 134919. • http://www.ibm.com/support/docview.wss?uid=ibm10716607 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1791
https://notcve.org/view.php?id=CVE-2017-1791
10 Jul 2018 — IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137036. IBM Rational Quality Manager, desde la versión 5.0 hasta la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los ... • http://www.ibm.com/support/docview.wss?uid=ibm10716607 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1792
https://notcve.org/view.php?id=CVE-2017-1792
10 Jul 2018 — IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137037. IBM Rational Quality Manager, desde la versión 5.0 hasta la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los ... • http://www.ibm.com/support/docview.wss?uid=ibm10716607 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1793
https://notcve.org/view.php?id=CVE-2017-1793
10 Jul 2018 — IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137038. IBM Rational Quality Manager, desde la versión 5.0 hasta la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los ... • http://www.ibm.com/support/docview.wss?uid=ibm10716607 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-1492
https://notcve.org/view.php?id=CVE-2018-1492
10 Jul 2018 — IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977. Los productos IBM Jazz Foundation podrían permitir que un usuario con acceso físico al sistema inicie sesión como otro usuario debido al error del servidor a la hora de cerrar la sesión anterior correctamente. IBM X-Force ID: 140977. • http://www.ibm.com/support/docview.wss?uid=ibm10716599 • CWE-384: Session Fixation •

CVE-2018-1523
https://notcve.org/view.php?id=CVE-2018-1523
10 Jul 2018 — IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141804. IBM Rational Quality Manager, de la versión 5.0 a la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuario... • http://www.ibm.com/support/docview.wss?uid=ibm10716607 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-1549
https://notcve.org/view.php?id=CVE-2018-1549
10 Jul 2018 — IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 142658. IBM Rational Quality Manager, de la versión 5.0 a la 5.0.2 y des... • http://www.ibm.com/support/docview.wss?uid=ibm10716607 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVE-2018-1396
https://notcve.org/view.php?id=CVE-2018-1396
10 Jul 2018 — IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138429. IBM Rational Quality Manager, de la versión 5.0 a la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuario... • http://www.ibm.com/support/docview.wss?uid=ibm10716607 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •