
CVE-2018-1766
https://notcve.org/view.php?id=CVE-2018-1766
29 Oct 2018 — IBM Team Concert (RTC) 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148620. IBM Team Concert (RTC), de la versión 5.0 a la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban có... • http://www.ibm.com/support/docview.wss?uid=ibm10737301 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-1558
https://notcve.org/view.php?id=CVE-2018-1558
02 Oct 2018 — IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142956. IBM Rational Collaborative Lifecycle Management, de la versión 5.0 a la 5.02 y desde la versión 6.0 hasta la 6.0.6, es vulnerable a Cross-Site Scripting (XSS). Esta vu... • http://www.ibm.com/support/docview.wss?uid=ibm10732477 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1753
https://notcve.org/view.php?id=CVE-2017-1753
20 Aug 2018 — Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 135655. Múltiples productos IBM Rational son vulnerables a inyección HTML. Un atacante remoto podría ejecutar código HTML malicioso que, cuando se visualice, se ejecutaría en el navegador web de la víctima en el contexto de seguridad del sitio anfitrión. • https://exchange.xforce.ibmcloud.com/vulnerabilities/135655 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2018-1394
https://notcve.org/view.php?id=CVE-2018-1394
20 Aug 2018 — Multiple IBM Rational products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138425. Múltiples productos IBM Rational son vulnerables a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidad... • https://exchange.xforce.ibmcloud.com/vulnerabilities/138425 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-1492
https://notcve.org/view.php?id=CVE-2018-1492
10 Jul 2018 — IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977. Los productos IBM Jazz Foundation podrían permitir que un usuario con acceso físico al sistema inicie sesión como otro usuario debido al error del servidor a la hora de cerrar la sesión anterior correctamente. IBM X-Force ID: 140977. • http://www.ibm.com/support/docview.wss?uid=ibm10716599 • CWE-384: Session Fixation •

CVE-2018-1423
https://notcve.org/view.php?id=CVE-2018-1423
10 Jul 2018 — IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in further attacks against the system. IBM X-Force ID: 139026. Los productos IBM Jazz Foundation podrían revelar información sensible a un atacante autenticado que podría conducir a más ataques contra el sistema. IBM X-Force ID: 139026. • http://www.ibm.com/support/docview.wss?uid=ibm10716599 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2018-1521
https://notcve.org/view.php?id=CVE-2018-1521
10 Jul 2018 — IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141802. IBM Rational Team Concert, de la versión 5.0 a la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embe... • https://exchange.xforce.ibmcloud.com/vulnerabilities/141802 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-1407
https://notcve.org/view.php?id=CVE-2018-1407
10 Jul 2018 — IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138445. IBM Rational Team Concert, de la versión 5.0 a la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embe... • https://exchange.xforce.ibmcloud.com/vulnerabilities/138445 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-1408
https://notcve.org/view.php?id=CVE-2018-1408
10 Jul 2018 — IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138446. IBM Rational Team Concert, de la versión 5.0 a la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embe... • https://exchange.xforce.ibmcloud.com/vulnerabilities/138446 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1700
https://notcve.org/view.php?id=CVE-2017-1700
24 Apr 2018 — IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM) could allow an authenticated user to cause a denial of service due to incorrect authorization for resource intensive scenarios. IBM X-Force ID: 134392. IBM Jazz Team ... • http://www.ibm.com/support/docview.wss?uid=swg22015635 • CWE-863: Incorrect Authorization •