CVE-2018-1549
https://notcve.org/view.php?id=CVE-2018-1549
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 142658. IBM Rational Quality Manager, de la versión 5.0 a la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, es vulnerable a ataques de separación de respuesta HTTP. • http://www.ibm.com/support/docview.wss?uid=ibm10716607 https://exchange.xforce.ibmcloud.com/vulnerabilities/142658 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •
CVE-2017-1488
https://notcve.org/view.php?id=CVE-2017-1488
An undisclosed vulnerability in Jazz common products exists with potential for information disclosure. IBM X-Force ID: 128627. Existe una vulnerabilidad no conocida en los productos comunes de Jazz que podría permitir la divulgación de información. IBM X-Force ID: 128627. • https://exchange.xforce.ibmcloud.com/vulnerabilities/128627 https://www-prd-trops.events.ibm.com/node/715709 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-1248
https://notcve.org/view.php?id=CVE-2017-1248
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124628. IBM Quality Manager (RQM) en versiones 5.0.x y desde la 6.0 hasta la 6.0.5 es vulnerable a inyección HTML. Un atacante remoto podría ejecutar código HTML malicioso que, cuando se visualiza, se ejecutaría en el navegador web de la víctima en el contexto de seguridad del sitio anfitrión. • http://www.ibm.com/support/docview.wss?uid=ibm10716201 https://exchange.xforce.ibmcloud.com/vulnerabilities/124628 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2017-1239
https://notcve.org/view.php?id=CVE-2017-1239
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID: 124357. IBM Quality Manager (RQM) en versiones 5.0.x y desde la 6.0 hasta la 6.0.5 podría revelar información sensible en respuestas de error "HTTP 500: Error interno del servidor". IBM X-Force ID: 124357. • http://www.ibm.com/support/docview.wss?uid=ibm10716201 https://exchange.xforce.ibmcloud.com/vulnerabilities/124357 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-1242
https://notcve.org/view.php?id=CVE-2017-1242
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124524. IBM Quality Manager (RQM) en versiones 5.0.x y desde la 6.0 hasta la 6.0.5 es vulnerable a inyección HTML. Un atacante remoto podría ejecutar código HTML malicioso que, cuando se visualiza, se ejecutaría en el navegador web de la víctima en el contexto de seguridad del sitio anfitrión. • http://www.ibm.com/support/docview.wss?uid=ibm10716201 https://exchange.xforce.ibmcloud.com/vulnerabilities/124524 • CWE-94: Improper Control of Generation of Code ('Code Injection') •