Page 4 of 35 results (0.002 seconds)

CVSS: 5.4EPSS: 0%CPEs: 54EXPL: 0

10 Dec 2013 — Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other products, allows remote authenticated users to inject arbitrary web script or HTML via vectors involving an IFRAME element. Vulenrabilidad Cross-site scripting (XSS) en la aplicación de búsqueda en IBM Rational Quality Manager (RQM) 2.0 a 2.0.1.1, 3.0.1.6 3.... • http://www-01.ibm.com/support/docview.wss?uid=swg21653689 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 4EXPL: 0

12 Sep 2013 — Open redirect vulnerability in IBM Rational Requirements Composer before 4.0.4 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. Vulnerabilidad de redirección abierta en IBM Rational Requirements Composer anterior a v4.0.4 permite a usuarios autenticados remotamente redireccionar a usuarios a sitios web arbitrarios y llevar a cabo ataques de phishing a través de una URL manipulada. • http://www-01.ibm.com/support/docview.wss?uid=swg21645927 • CWE-20: Improper Input Validation •

CVSS: 7.8EPSS: 0%CPEs: 4EXPL: 0

12 Sep 2013 — Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for local users to gain privileges via unknown vectors. Vulnerabilidad sin especificar en IBM Rational Requirements Composer anterior a 4.0.4 facilita a atacantes locales escalar privilegios través de vectores desconocidos • http://www-01.ibm.com/support/docview.wss?uid=swg21645927 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 7.5EPSS: 0%CPEs: 4EXPL: 0

12 Sep 2013 — Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for remote attackers to discover credentials via unknown vectors. Vulnerabilidad sin especificar en IBM Rational Requirements Composer anterior a 4.0.4 facilita a atacantes remotos descubrir credenciales a través de vectores desconocidos • http://www-01.ibm.com/support/docview.wss?uid=swg21645927 • CWE-255: Credentials Management Errors •

CVSS: 9.8EPSS: 0%CPEs: 4EXPL: 0

12 Sep 2013 — IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors. IBM Rational Requirements Composer anterior a v4.0.4 no realiza una autenticación adecuada, lo cual tiene un impacto no especificado y vectores de ataque remotos. • http://www-01.ibm.com/support/docview.wss?uid=swg21645927 • CWE-287: Improper Authentication •