cbcvebase.

Ibm Rational Doors Next Generation vulnerabilities

164 known vulnerabilities affecting ibm/rational_doors_next_generation.

Total CVEs
164
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH8MEDIUM146LOW10

Vulnerabilities

Page 4 of 9
CVE-2021-29668P4MEDIUMCVSS 5.4v6.0.6v6.0.6.1+3 more2021-06-02
CVE-2021-29668 [MEDIUM] CWE-79 CVE-2021-29668: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199406.
nvd
CVE-2020-5030P4MEDIUMCVSS 5.4v6.0.6v6.0.6.1+3 more2021-06-02
CVE-2020-5030 [MEDIUM] CWE-79 CVE-2020-5030: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193737.
nvd
CVE-2021-20338P4MEDIUMCVSS 5.4v6.0.6v6.0.6.1+3 more2021-06-02
CVE-2021-20338 [MEDIUM] CWE-79 CVE-2021-20338: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194449.
nvd
CVE-2021-29670P4MEDIUMCVSS 5.4v6.0.6v6.0.6.1+3 more2021-06-02
CVE-2021-29670 [MEDIUM] CWE-79 CVE-2021-29670: IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulner IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199408.
nvd
CVE-2020-4977P4MEDIUMCVSS 5.4v6.0.6v6.0.6.1+3 more2021-06-02
CVE-2020-4977 [MEDIUM] CWE-79 CVE-2020-4977: IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. Th IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192470.
nvd
CVE-2021-29673P4MEDIUMCVSS 5.4v7.0v7.0.1+3 more2021-10-27
CVE-2021-29673 [MEDIUM] CWE-79 CVE-2021-29673: IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows user IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199482.
nvd
CVE-2021-29713P4MEDIUMCVSS 5.4v6.0.2v6.0.6+4 more2021-10-27
CVE-2021-29713 [MEDIUM] CWE-79 CVE-2021-29713: IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows user IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2018-1492P4MEDIUMCVSS 6.8≥ 5.0, ≤ 5.0.2≥ 6.0.0, ≤ 6.0.5+9 more2018-07-10
CVE-2018-1492 [MEDIUM] CWE-384 CVE-2018-1492: IBM Jazz Foundation products could allow a user with physical access to the system to log in as anot IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977.
nvd
CVE-2018-1507P4MEDIUMCVSS 5.4v6.0.52018-06-27
CVE-2018-1507 [MEDIUM] CWE-79 CVE-2018-1507: IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141415.
nvd
CVE-2018-1913P4MEDIUMCVSS 5.4v5.0.2v5.0+8 more2019-04-03
CVE-2018-1913 [MEDIUM] CWE-79 CVE-2018-1913: IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-s IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152737.
nvd
CVE-2018-1688P4MEDIUMCVSS 5.4≥ 5.0, ≤ 6.0.62019-03-14
CVE-2018-1688 [MEDIUM] CWE-79 CVE-2018-1688: IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerabl IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145509.
nvd
CVE-2018-1762P4MEDIUMCVSS 5.4≥ 5.0.0, ≤ 5.0.2≥ 6.0.0, ≤ 6.0.62018-11-29
CVE-2018-1762 [MEDIUM] CWE-79 CVE-2018-1762: IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerab IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148616.
nvd
CVE-2018-1422P4MEDIUMCVSS 5.4≥ 5.0, ≤ 5.0.2≥ 6.0.0, ≤ 6.0.5+9 more2018-08-06
CVE-2018-1422 [MEDIUM] CWE-79 CVE-2018-1422: IBM Jazz Foundation products (IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6 IBM Jazz Foundation products (IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.5) are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID
nvd
CVE-2018-1529P4MEDIUMCVSS 5.4≥ 5.0.0, ≤ 5.0.2≥ 6.0.0, ≤ 6.0.52018-07-19
CVE-2018-1529 [MEDIUM] CWE-79 CVE-2018-1529: IBM Rational DOORS Next Generation 5.0 through 5.0.2, 6.0 through 6.0.5 and IBM Rational Requirement IBM Rational DOORS Next Generation 5.0 through 5.0.2, 6.0 through 6.0.5 and IBM Rational Requirements Composer 5.0 through 5.0.2 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted
nvd
CVE-2017-1629P4MEDIUMCVSS 5.4≥ 4.0.1, ≤ 4.0.7≥ 5.0, ≤ 5.0.2+1 more2018-03-23
CVE-2017-1629 [MEDIUM] CWE-79 CVE-2017-1629: IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to c IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133127.
nvd
CVE-2017-1655P4MEDIUMCVSS 5.4≥ 4.0.1, ≤ 4.0.7≥ 5.0, ≤ 5.0.2+1 more2018-03-23
CVE-2017-1655 [MEDIUM] CWE-79 CVE-2017-1655: IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to c IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133379.
nvd
CVE-2017-1762P4MEDIUMCVSS 5.4≥ 4.0.1, ≤ 4.0.7≥ 5.0, ≤ 5.0.2+1 more2018-03-23
CVE-2017-1762 [MEDIUM] CWE-79 CVE-2017-1762: IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to c IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136006.
nvd
CVE-2017-1560P4MEDIUMCVSS 5.4≥ 4.0, ≤ 4.0.7≥ 5.0, ≤ 5.0.2+10 more2017-11-27
CVE-2017-1560 [MEDIUM] CWE-79 CVE-2017-1560: IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vu IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131759.
nvd
CVE-2017-1461P4MEDIUMCVSS 5.4≥ 4.0, ≤ 4.0.7≥ 5.0, ≤ 5.0.2+10 more2017-11-27
CVE-2017-1461 [MEDIUM] CWE-79 CVE-2017-1461: IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vu IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128460.
nvd
CVE-2017-1678P4MEDIUMCVSS 5.4≥ 4.0, ≤ 4.0.7≥ 5.0, ≤ 5.0.2+10 more2017-11-27
CVE-2017-1678 [MEDIUM] CWE-79 CVE-2017-1678: IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vu IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134000.
nvd
Ibm Rational Doors Next Generation vulnerabilities | cvebase