cbcvebase.

Ibm Rational Collaborative Lifecycle Management vulnerabilities

171 known vulnerabilities affecting ibm/rational_collaborative_lifecycle_management.

Total CVEs
171
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH9MEDIUM155LOW6

Vulnerabilities

Page 4 of 9
CVE-2020-4733P4MEDIUMCVSS 5.4v6.0.2v6.0.6+1 more2021-01-08
CVE-2020-4733 [MEDIUM] CWE-79 CVE-2020-4733: IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188127.
nvd
CVE-2020-4697P4MEDIUMCVSS 5.4v6.0.2v6.0.6+1 more2021-01-08
CVE-2020-4697 [MEDIUM] CWE-79 CVE-2020-4697: IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186790.
nvd
CVE-2020-4691P4MEDIUMCVSS 5.4v6.0.2v6.0.6+1 more2021-01-08
CVE-2020-4691 [MEDIUM] CWE-79 CVE-2020-4691: IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186698.
nvd
CVE-2020-5031P4MEDIUMCVSS 5.4v6.0.6v6.0.6.12021-07-19
CVE-2020-5031 [MEDIUM] CWE-79 CVE-2020-5031: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193738.
nvd
CVE-2021-20507P4MEDIUMCVSS 5.4v6.0.6v6.0.6.12021-07-19
CVE-2021-20507 [MEDIUM] CWE-79 CVE-2021-20507: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198235.
nvd
CVE-2021-29668P4MEDIUMCVSS 5.4v6.0.6v6.0.6.12021-06-02
CVE-2021-29668 [MEDIUM] CWE-79 CVE-2021-29668: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199406.
nvd
CVE-2020-5030P4MEDIUMCVSS 5.4v6.0.6v6.0.6.12021-06-02
CVE-2020-5030 [MEDIUM] CWE-79 CVE-2020-5030: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193737.
nvd
CVE-2021-20338P4MEDIUMCVSS 5.4v6.0.6v6.0.6.12021-06-02
CVE-2021-20338 [MEDIUM] CWE-79 CVE-2021-20338: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194449.
nvd
CVE-2021-29670P4MEDIUMCVSS 5.4v6.0.6v6.0.6.12021-06-02
CVE-2021-29670 [MEDIUM] CWE-79 CVE-2021-29670: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199408.
nvd
CVE-2020-4977P4MEDIUMCVSS 5.4v6.0.6v6.0.6.12021-06-02
CVE-2020-4977 [MEDIUM] CWE-79 CVE-2020-4977: IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. Th IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192470.
nvd
CVE-2021-29673P4MEDIUMCVSS 5.4v6.0.1v6.0.6+1 more2021-10-27
CVE-2021-29673 [MEDIUM] CWE-79 CVE-2021-29673: IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows user IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199482.
nvd
CVE-2021-29713P4MEDIUMCVSS 5.4v6.0.6v6.0.6.1+2 more2021-10-27
CVE-2021-29713 [MEDIUM] CWE-79 CVE-2021-29713: IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows user IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2018-1492P4MEDIUMCVSS 6.8≥ 5.0, ≤ 6.0.5v5.0+8 more2018-07-10
CVE-2018-1492 [MEDIUM] CWE-384 CVE-2018-1492: IBM Jazz Foundation products could allow a user with physical access to the system to log in as anot IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977.
nvd
CVE-2018-1825P4MEDIUMCVSS 5.4≥ 5.0, ≤ 6.0.62019-03-14
CVE-2018-1825 [MEDIUM] CWE-79 CVE-2018-1825: IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerabi IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150428.
nvd
CVE-2018-1688P4MEDIUMCVSS 5.4≥ 5.0, ≤ 6.0.6v5.0+9 more2019-03-14
CVE-2018-1688 [MEDIUM] CWE-79 CVE-2018-1688: IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerabl IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145509.
nvd
CVE-2018-1824P4MEDIUMCVSS 5.4≥ 5.0, ≤ 6.0.62019-03-14
CVE-2018-1824 [MEDIUM] CWE-79 CVE-2018-1824: IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerabi IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150427.
nvd
CVE-2018-1829P4MEDIUMCVSS 5.4≥ 5.0, ≤ 6.0.62019-03-14
CVE-2018-1829 [MEDIUM] CWE-79 CVE-2018-1829: IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerabi IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150432.
nvd
CVE-2018-1823P4MEDIUMCVSS 5.4≥ 5.0, ≤ 6.0.62019-03-14
CVE-2018-1823 [MEDIUM] CWE-79 CVE-2018-1823: IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerabi IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150426.
nvd
CVE-2018-1762P4MEDIUMCVSS 5.4≥ 5.0.0, ≤ 6.0.6v5.0+9 more2018-11-29
CVE-2018-1762 [MEDIUM] CWE-79 CVE-2018-1762: IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerab IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148616.
nvd
CVE-2017-1629P4MEDIUMCVSS 5.4≥ 4.0, ≤ 6.0.5v5.0+8 more2018-03-23
CVE-2017-1629 [MEDIUM] CWE-79 CVE-2017-1629: IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to c IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133127.
nvd
Ibm Rational Collaborative Lifecycle Management vulnerabilities | cvebase