Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Rational_engineering_lifecycle_manager
(Ibm)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 141 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-03-30 | CVE-2021-20518 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198437. | Engineering_insights, Engineering_lifecycle_management, Engineering_requirements_quality_assistant_on\-Premises, Engineering_workflow_management, Rational_engineering_lifecycle_manager, Rational_team_concert | 5.4 | ||
2021-03-30 | CVE-2021-20506 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198231. | Engineering_insights, Engineering_lifecycle_management, Engineering_requirements_quality_assistant_on\-Premises, Engineering_workflow_management, Rational_engineering_lifecycle_manager, Rational_team_concert | 5.4 | ||
2021-03-30 | CVE-2021-20504 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198231. | Engineering_insights, Engineering_lifecycle_management, Engineering_requirements_quality_assistant_on\-Premises, Engineering_workflow_management, Rational_engineering_lifecycle_manager, Rational_team_concert | 5.4 | ||
2021-03-30 | CVE-2021-20503 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198182. | Engineering_insights, Engineering_lifecycle_management, Engineering_requirements_quality_assistant_on\-Premises, Engineering_workflow_management, Rational_engineering_lifecycle_manager, Rational_team_concert | 5.4 | ||
2021-03-30 | CVE-2021-20502 | IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 198059. | Engineering_insights, Engineering_lifecycle_management, Engineering_requirements_quality_assistant_on\-Premises, Engineering_workflow_management, Rational_engineering_lifecycle_manager, Rational_team_concert | 7.1 | ||
2021-03-30 | CVE-2021-20447 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196623. | Engineering_insights, Engineering_lifecycle_management, Engineering_requirements_quality_assistant_on\-Premises, Engineering_workflow_management, Rational_engineering_lifecycle_manager, Rational_team_concert | 5.4 | ||
2021-03-30 | CVE-2021-20352 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194710. | Engineering_insights, Engineering_lifecycle_management, Engineering_requirements_quality_assistant_on\-Premises, Engineering_workflow_management, Rational_engineering_lifecycle_manager, Rational_team_concert | 5.4 | ||
2021-01-27 | CVE-2021-20357 | IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194963. | Collaborative_lifecycle_management, Engineering_insights, Engineering_lifecycle_management, Engineering_requirements_management_doors_next, Engineering_test_management, Engineering_workflow_management, Global_configuration_management, Rational_engineering_lifecycle_manager, Rational_quality_manager, Rhapsody_design_manager, Rhapsody_model_manager | 5.4 | ||
2021-01-27 | CVE-2020-4865 | IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741. | Collaborative_lifecycle_management, Engineering_insights, Engineering_lifecycle_management, Engineering_requirements_management_doors_next, Engineering_test_management, Engineering_workflow_management, Global_configuration_management, Rational_engineering_lifecycle_manager, Rational_quality_manager, Rhapsody_design_manager, Rhapsody_model_manager | 5.4 | ||
2021-01-27 | CVE-2020-4855 | IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190457. | Collaborative_lifecycle_management, Engineering_insights, Engineering_lifecycle_management, Engineering_requirements_management_doors_next, Engineering_test_management, Engineering_workflow_management, Global_configuration_management, Rational_engineering_lifecycle_manager, Rational_quality_manager, Rhapsody_design_manager, Rhapsody_model_manager | 5.4 |