CVE-2018-1824
https://notcve.org/view.php?id=CVE-2018-1824
IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150427. IBM Rational Quality Manager, desde la versión 5.0 hasta la 6.0.6, es vulnerable a Cross-Site Scripting. Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • http://www.ibm.com/support/docview.wss?uid=ibm10875318 http://www.securityfocus.com/bid/107433 https://exchange.xforce.ibmcloud.com/vulnerabilities/150427 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-1825
https://notcve.org/view.php?id=CVE-2018-1825
IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150428. IBM Rational Quality Manager, desde la versión 5.0 hasta la 6.0.6, es vulnerable a Cross-Site Scripting. Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • http://www.ibm.com/support/docview.wss?uid=ibm10875318 http://www.securityfocus.com/bid/107433 https://exchange.xforce.ibmcloud.com/vulnerabilities/150428 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-1829
https://notcve.org/view.php?id=CVE-2018-1829
IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150432. IBM Rational Quality Manager, desde la versión 5.0 hasta la 6.0.6, es vulnerable a Cross-Site Scripting. Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • http://www.ibm.com/support/docview.wss?uid=ibm10875318 http://www.securityfocus.com/bid/107433 https://exchange.xforce.ibmcloud.com/vulnerabilities/150432 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-1658
https://notcve.org/view.php?id=CVE-2018-1658
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to HTTP header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to inject arbitrary HTTP headers, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 144884. IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management, desde la versión 5.0 hasta la 6.0.6) es vulnerable a la inyección de cabeceras HTTP, provocado por la validación incorrecta de entradas. Mediante la persuasión de una víctima para que visite una página web especialmente manipulada, un atacante remoto podría explotar esta vulnerabilidad para inyectar cabeceras HTTP arbitrarias, lo que permitirá que el atacante lleve a cabo varios ataques contra el sistema vulnerable, incluidos el Cross-Site Scripting (XSS), envenenamiento de caché o secuestro de sesión. • http://www.ibm.com/support/docview.wss?uid=ibm10875340 http://www.securityfocus.com/bid/107435 https://exchange.xforce.ibmcloud.com/vulnerabilities/144884 • CWE-20: Improper Input Validation •
CVE-2018-1762
https://notcve.org/view.php?id=CVE-2018-1762
IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148616. IBM Rational Collaborative Lifecycle Management desde la versión 5.0 hasta la 5.0.2 y desde la versión 6.0 hasta la 6.0.6, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • http://www.securityfocus.com/bid/106053 https://exchange.xforce.ibmcloud.com/vulnerabilities/148616 https://www.ibm.com/support/docview.wss?uid=ibm10742281 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •