Page 6 of 37 results (0.011 seconds)

CVSS: 7.5EPSS: 0%CPEs: 7EXPL: 0

ClearQuest Web in IBM Rational ClearQuest MultiSite before 7.1 allows remote servers to direct a client's submissions and changes to an arbitrary database by specifying multiple comma-separated server identifiers on the JTLRMIREGISTRYSERVERS line in a jtl.properties file. ClearQuest Web en IBM Rational ClearQuest MultiSite anteriores a la v7.1 permitiría a atacantes remotos dirigir envíos del cliente y cambios a una base de datos de su elección especificando unos identificadores de servidor separados por múltiples comas en la linea JTLRMIREGISTRYSERVERS del fichero jtl.properties. • http://secunia.com/advisories/32847 http://www-01.ibm.com/support/docview.wss?uid=swg1PK38745 https://exchange.xforce.ibmcloud.com/vulnerabilities/46993 •

CVSS: 4.3EPSS: 0%CPEs: 7EXPL: 1

Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO of a URI associated with a VOB page. Múltiples vulnerabilidades de secuencias de ejecución de comandos en sitios cruzados en la interfaz web de ClearCase RWP server en IBM Rational ClearCase v7.0.0 anterior a la v7.0.0.4, y v7.0.1.1-RATL-RCC-IFIX02 y posiblemente v7.0.1 anteriores a v7.0.1.3, permitiria a atacantes remotos inyectar secuencias de comandos web o HTML a traves de PATH_INFO de un URI asociado con una pagina VOB. • https://www.exploit-db.com/exploits/32631 http://secunia.com/advisories/32957 http://securitytracker.com/id?1021295 http://www-01.ibm.com/support/docview.wss?uid=swg1PK70972 http://www.securityfocus.com/bid/32574 http://www.vupen.com/english/advisories/2008/3330 https://exchange.xforce.ibmcloud.com/vulnerabilities/46983 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de secuencias de ejecución de comandos en sitios cruzados en CQ Web en IBM Rational ClearQuest v7.0.0 anterior a la v7.0.0.4 y 7.0.1 anterior a la v7.0.1.3 permitiría a atacantes remotos inyectar secuencias de comandos web o HTML a su elección a través de vectores no específicos. • http://secunia.com/advisories/32847 http://www-01.ibm.com/support/docview.wss?uid=swg1PK69316 http://www.osvdb.org/50369 http://www.securityfocus.com/bid/32576 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 9EXPL: 0

The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7 before 7.1 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree. La herramienta ClearQuest Maintenance en IBM Rational ClearQuest v7 anterior a la v7.1 almacena la contraseña de la base de datos en texto claro en un objeto en un perfil de conexión de ClearQuest o un fichero de exportación, que permitiría a usuarios remotos autenticados obtener información sensible localizando el objeto contraseña en el árbol de objetos. • http://secunia.com/advisories/32847 http://www-01.ibm.com/support/docview.wss?uid=swg1PK65908 https://exchange.xforce.ibmcloud.com/vulnerabilities/46995 • CWE-255: Credentials Management Errors •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a combination of ?script? and ?/script? sequences in the id field, possibly related to a cross-site scripting (XSS) vulnerability. • http://www-1.ibm.com/support/docview.wss?uid=swg1PK68332 http://www.securitytracker.com/id?1020642 http://www.vupen.com/english/advisories/2008/2317 https://exchange.xforce.ibmcloud.com/vulnerabilities/44254 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •