Page 11 of 52 results (0.005 seconds)

CVSS: 5.0EPSS: 0%CPEs: 105EXPL: 0

IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. IBM Jazz Team Server, utilizado en Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x anterior a 3.0.1.6 iFix 3, 4.x anterior a 4.0.7, y 5.x anterior a 5.0.1; y otros productos Rational, no configura el indicador de seguridad para la cookie de la sesión en una sesión https, lo que facilita a atacantes remotos capturar esta cookie mediante la intercepción de su transmisión dentro de una sesión http. • http://www-01.ibm.com/support/docview.wss?uid=swg21682787 https://exchange.xforce.ibmcloud.com/vulnerabilities/94258 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 3.5EPSS: 0%CPEs: 17EXPL: 0

IBM Rational Team Concert (RTC) 3.x before 3.0.1.6 IF3 and 4.x before 4.0.7 does not properly integrate with build engines, which allows remote authenticated users to discover credentials via unspecified vectors. IBM Rational Team Concert (RTC) 3.x anterior a 3.0.1.6 IF3 y 4.x anterior a 4.0.7 no integra debidamente con los motores build, lo que permite a usuarios remotos autenticados descubrir las credenciales a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg21679192 https://exchange.xforce.ibmcloud.com/vulnerabilities/93436 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •