Ibm Rational Collaborative Lifecycle Management vulnerabilities
171 known vulnerabilities affecting ibm/rational_collaborative_lifecycle_management.
Total CVEs
171
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH9MEDIUM155LOW6
Vulnerabilities
Page 7 of 9
CVE-2017-1280P4MEDIUMCVSS 5.4v5.0.0v5.0.1+9 more2018-07-03
CVE-2017-1280 [MEDIUM] CWE-79 CVE-2017-1280: IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 a
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2017-1281P4MEDIUMCVSS 5.4v5.0.0v5.0.1+9 more2018-07-03
CVE-2017-1281 [MEDIUM] CWE-79 CVE-2017-1281: IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 a
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2017-1294P4MEDIUMCVSS 5.4v5.0.0v5.0.1+9 more2018-07-03
CVE-2017-1294 [MEDIUM] CWE-79 CVE-2017-1294: IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 a
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-6032P4MEDIUMCVSS 5.4v4.0.0v4.0.1+13 more2017-02-08
CVE-2016-6032 [MEDIUM] CWE-79 CVE-2016-6032: IBM Rational Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability
IBM Rational Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2018-1892P4MEDIUMCVSS 5.4≥ 6.0, ≤ 6.0.6.1v6.0+7 more2019-06-27
CVE-2018-1892 [MEDIUM] CWE-79 CVE-2018-1892: IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scri
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152156.
nvd
CVE-2018-1826P4MEDIUMCVSS 5.4≥ 6.0, ≤ 6.0.6.1v6.0+7 more2019-06-27
CVE-2018-1826 [MEDIUM] CWE-79 CVE-2018-1826: IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scri
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150429.
nvd
CVE-2018-1893P4MEDIUMCVSS 5.4≥ 6.0, ≤ 6.0.6.1v6.0+7 more2019-06-27
CVE-2018-1893 [MEDIUM] CWE-79 CVE-2018-1893: IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scri
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152157.
nvd
CVE-2018-1827P4MEDIUMCVSS 5.4≥ 6.0, ≤ 6.0.6.1v6.0+7 more2019-06-27
CVE-2018-1827 [MEDIUM] CWE-79 CVE-2018-1827: IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scri
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150430.
nvd
CVE-2018-1758P4MEDIUMCVSS 5.4≥ 6.0, ≤ 6.0.6.1v6.0+7 more2019-06-27
CVE-2018-1758 [MEDIUM] CWE-79 CVE-2018-1758: IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scri
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148605.
nvd
CVE-2018-1760P4MEDIUMCVSS 5.4≥ 6.0, ≤ 6.0.6.1v6.0+7 more2019-06-27
CVE-2018-1760 [MEDIUM] CWE-79 CVE-2018-1760: IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scri
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148614.
nvd
CVE-2018-1828P4MEDIUMCVSS 5.4≥ 6.0, ≤ 6.0.6.1v6.0+7 more2019-06-27
CVE-2018-1828 [MEDIUM] CWE-79 CVE-2018-1828: IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scri
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150431.
nvd
CVE-2017-1365P4MEDIUMCVSS 5.4≥ 4.0.0, ≤ 6.0.4v4.0+16 more2017-12-27
CVE-2017-1365 [MEDIUM] CWE-79 CVE-2017-1365: IBM Team Concert (RTC including IBM Rational Collaborative Lifecycle Management 4.0, 5.0., and 6.0)
IBM Team Concert (RTC including IBM Rational Collaborative Lifecycle Management 4.0, 5.0., and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 126858
nvd
CVE-2016-6030P4MEDIUMCVSS 5.4v4.0.0v4.0.1+12 more2017-02-01
CVE-2016-6030 [MEDIUM] CWE-79 CVE-2016-6030: IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-6061P4MEDIUMCVSS 5.4v4.0.0v4.0.1+12 more2017-02-01
CVE-2016-6061 [MEDIUM] CWE-79 CVE-2016-6061: IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2020-5004P4MEDIUMCVSS 5.4v6.0.2v6.0.6+1 more2021-07-28
CVE-2020-5004 [MEDIUM] CWE-79 CVE-2020-5004: IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192957.
nvd
CVE-2016-6040P4MEDIUMCVSS 5.0v4.0.0v4.0.1+12 more2017-02-01
CVE-2016-6040 [MEDIUM] CWE-384 CVE-2016-6040: IBM Jazz Foundation could allow an authenticated user to take over a previously logged in user due t
IBM Jazz Foundation could allow an authenticated user to take over a previously logged in user due to session expiration not being enforced.
nvd
CVE-2016-0331P4MEDIUMCVSS 5.4v6.0.1v6.0.22016-09-12
CVE-2016-0331 [MEDIUM] CWE-79 CVE-2016-0331: Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 6.0.1 and 6.0.2 before 6.0.2 i
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 6.0.1 and 6.0.2 before 6.0.2 iFix2 and Rational Collaborative Lifecycle Management 6.0.1 and 6.0.2 before 6.0.2 iFix2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2017-1099P4MEDIUMCVSS 4.3v4.0v4.0.2+13 more2017-06-13
CVE-2017-1099 [MEDIUM] CWE-200 CVE-2017-1099: IBM Jazz Foundation could expose potentially sensitive information to authenticated users through st
IBM Jazz Foundation could expose potentially sensitive information to authenticated users through stack trace error conditions. IBM X-Force ID: 120659.
nvd
CVE-2015-0112P4MEDIUMCVSS 4.0v3.0.1v3.0.1.1+16 more2015-06-07
CVE-2015-0112 [MEDIUM] CVE-2015-0112: Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1,
Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1, 4.x before 4.0.7 IF5, and 5.x before 5.0.2 IF4; Rational Quality Manager (RQM) 2.0 through 2.0.1, 3.0 through 3.0.1.6, 4.0 through 4.0.7, and 5.0 through 5.0.2; Rational Team Concert (RTC) 2.0 through 2.0.0.2, 3.x before 3.0.1.6 IF6, 4.x before 4.0.7 IF5, and 5.
nvd
CVE-2017-1524P4MEDIUMCVSS 4.3≥ 4.0.0, ≤ 6.0.5v5.0+8 more2018-03-23
CVE-2017-1524 [MEDIUM] CWE-200 CVE-2017-1524: IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an aut
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request that could be used to aid future attacks. IBM X-Force ID: 129970.
nvd