CVE-2018-1423
https://notcve.org/view.php?id=CVE-2018-1423
IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in further attacks against the system. IBM X-Force ID: 139026. Los productos IBM Jazz Foundation podrían revelar información sensible a un atacante autenticado que podría conducir a más ataques contra el sistema. IBM X-Force ID: 139026. • http://www.ibm.com/support/docview.wss?uid=ibm10716599 https://exchange.xforce.ibmcloud.com/vulnerabilities/139026 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-1492
https://notcve.org/view.php?id=CVE-2018-1492
IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977. Los productos IBM Jazz Foundation podrían permitir que un usuario con acceso físico al sistema inicie sesión como otro usuario debido al error del servidor a la hora de cerrar la sesión anterior correctamente. IBM X-Force ID: 140977. • http://www.ibm.com/support/docview.wss?uid=ibm10716599 https://exchange.xforce.ibmcloud.com/vulnerabilities/140977 • CWE-384: Session Fixation •
CVE-2018-1396
https://notcve.org/view.php?id=CVE-2018-1396
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138429. IBM Rational Quality Manager, de la versión 5.0 a la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • http://www.ibm.com/support/docview.wss?uid=ibm10716607 https://exchange.xforce.ibmcloud.com/vulnerabilities/138429 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-1738
https://notcve.org/view.php?id=CVE-2017-1738
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 contains an undisclosed vulnerability that would allow an authenticated user to obtain elevated privileges. IBM X-Force ID: 134919. IBM Rational Quality Manager, desde la versión 5.0 hasta la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, contiene una vulnerabilidad sin revelar que permitiría que un usuario autenticado obtenga privilegios elevados. IBM X-Force ID: 134919. • http://www.ibm.com/support/docview.wss?uid=ibm10716607 https://exchange.xforce.ibmcloud.com/vulnerabilities/134919 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-1791
https://notcve.org/view.php?id=CVE-2017-1791
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137036. IBM Rational Quality Manager, desde la versión 5.0 hasta la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • http://www.ibm.com/support/docview.wss?uid=ibm10716607 https://exchange.xforce.ibmcloud.com/vulnerabilities/137036 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •