Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Rational_requirements_composer
(Ibm)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 38 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2015-03-18 | CVE-2014-6129 | IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational DOORS Next Generation 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Requirements Composer 2.x and 3.x... | Rational_collaborative_lifecycle_management, Rational_doors_next_generation, Rational_quality_manager, Rational_requirements_composer, Rational_team_concert | N/A | ||
2014-09-11 | CVE-2014-3092 | IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. | Rational_doors_next_generation, Rational_engineering_lifecycle_manager, Rational_quality_manager, Rational_requirements_composer, Rational_rhapsody_design_manager, Rational_software_architect_design_manager, Rational_team_concert | N/A | ||
2014-03-04 | CVE-2014-0846 | Cross-site scripting (XSS) vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | Rational_doors_next_generation, Rational_requirements_composer | N/A | ||
2014-03-04 | CVE-2014-0845 | Open redirect vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. | Rational_doors_next_generation, Rational_requirements_composer | N/A | ||
2014-03-04 | CVE-2014-0844 | Unspecified vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to read arbitrary data via unknown vectors. | Rational_doors_next_generation, Rational_requirements_composer | N/A | ||
2013-12-10 | CVE-2013-5404 | Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other products, allows remote authenticated users to inject arbitrary web script or HTML via vectors involving an IFRAME element. | Rational_quality_manager, Rational_requirements_composer, Rational_team_concert | N/A | ||
2013-09-12 | CVE-2013-3039 | IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors. | Rational_requirements_composer | N/A | ||
2013-09-12 | CVE-2013-3038 | Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for remote attackers to discover credentials via unknown vectors. | Rational_requirements_composer | N/A | ||
2013-09-12 | CVE-2013-3037 | Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for local users to gain privileges via unknown vectors. | Rational_requirements_composer | N/A | ||
2013-09-12 | CVE-2013-3036 | Open redirect vulnerability in IBM Rational Requirements Composer before 4.0.4 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. | Rational_requirements_composer | N/A |