Page 9 of 86 results (0.010 seconds)

CVSS: 5.4EPSS: 0%CPEs: 13EXPL: 0

02 Oct 2018 — IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142956. IBM Rational Collaborative Lifecycle Management, de la versión 5.0 a la 5.02 y desde la versión 6.0 hasta la 6.0.6, es vulnerable a Cross-Site Scripting (XSS). Esta vu... • http://www.ibm.com/support/docview.wss?uid=ibm10732477 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 2EXPL: 0

25 Sep 2018 — IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561. IBM Rational Engineering Lifecycle Manager, desde la versión 5.0 hasta la 5.02 y desde la versión 6.0 hasta la 6.0.6, podría permitir que atacantes remotos omitan la autenticación mediante una petición directa o navegación forzada a una página distinta de la URL planeada. IBM ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/142561 • CWE-287: Improper Authentication •

CVSS: 5.4EPSS: 0%CPEs: 2EXPL: 0

25 Sep 2018 — IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142958. IBM Rational Engineering Lifecycle Manager, de la versión 5.0 a la 5.02 y desde la versión 6.0 hasta la 6.0.6, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilida... • https://exchange.xforce.ibmcloud.com/vulnerabilities/142958 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.1EPSS: 0%CPEs: 2EXPL: 0

25 Sep 2018 — IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 143501. IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager de la versión 5.0 a la 5.02 y de la versión 6.0 a la 6.0.6) es vulnerable a ataques de tipo XML External Entity Injectio... • https://exchange.xforce.ibmcloud.com/vulnerabilities/143501 • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 7.1EPSS: 0%CPEs: 2EXPL: 0

25 Sep 2018 — IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 143797. IBM Rational Engineering Lifecycle Manager de la versión 5.0 a la 5.02 y de la versión 6.0 a la 6.0.6 es vulnerable a ataques de tipo XML External Entity Injection (XXE) al procesar datos XML. Un atacante r... • https://exchange.xforce.ibmcloud.com/vulnerabilities/143797 • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 5.4EPSS: 0%CPEs: 2EXPL: 0

25 Sep 2018 — IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144885. IBM Rational Engineering Lifecycle Manager, de la versión 5.0 a la 5.02 y desde la versión 6.0 hasta la 6.0.6, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilida... • https://exchange.xforce.ibmcloud.com/vulnerabilities/144885 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •