CVE-2017-1249
published 2017-07-24CVE-2017-1249: IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus…
PriorityP423medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.65%
46.8th percentile
IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rhapsody_design_manager | — | — |
| ibm | rhapsody_design_manager | — | — |
| ibm | rhapsody_design_manager | — | — |
| ibm | rhapsody_design_manager | — | — |
| ibm | rhapsody_design_manager | — | — |
| ibm | rhapsody_design_manager | — | — |
| ibm | rhapsody_design_manager | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libdbd-mysql-perl vulnerabilities
osv·2025-04-07·CVSS 5.9
CVE-2016-1249 libdbd-mysql-perl vulnerabilities
libdbd-mysql-perl vulnerabilities
It was discovered that libdbd-mysql-perl did not correctly handle certain
SQL queries. An attacker could possibly use this issue to cause a denial
of service. (CVE-2016-1249)
It was discovered that libdbd-mysql-perl did not correctly handle certain
memory operations, which could lead to a use-after-free vulnerability. A
remote attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2016-1251, CVE-2017-10788)
It was discovered that libdbd-mysql-perl did not properly enforce SSL
connections depending on the mysql_ssl setting. A machine-in-the-middle
attacker could possibly use this issue to spoof servers. (CVE-2017-10789)
GHSA
GHSA-h75x-x922-h28v: IBM Rhapsody DM 5
ghsa_unreviewed·2022-05-17
CVE-2017-1249 [MEDIUM] CWE-79 GHSA-h75x-x922-h28v: IBM Rhapsody DM 5
IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
OSV
libdbd-mysql-perl vulnerabilities
osv·2022-04-01·CVSS 5.9
CVE-2016-1249 libdbd-mysql-perl vulnerabilities
libdbd-mysql-perl vulnerabilities
It was discovered that the DBD::mysql module, when configured with server-side
prepared statement support, was susceptible to operations that would result in
improper memory access. An attacker could possibly use this issue to cause
DBD::mysql to crash, resulting in a denial of service.
(CVE-2016-1249, CVE-2016-1251)
It was discovered that the DBD::mysql module was susceptible to an operation
that would result in improper memory access, introduced through incorrect
documentation and code examples. An attacker could possibly use this issue to
cause DBD::mysql to crash or potentially cause other, unspecified, impact.
(CVE-2017-10788)
It was discovered that the DBD::mysql module processed SSL/TLS settings in a
way that did not fully correlate with the resp
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-07-24
Published