Ibm Rational Doors Next Generation vulnerabilities
164 known vulnerabilities affecting ibm/rational_doors_next_generation.
Total CVEs
164
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8MEDIUM146LOW10
Vulnerabilities
Page 5 of 9
CVE-2018-1394MEDIUMCVSS 5.4≥ 5.0.0, ≤ 5.0.2≥ 6.0.0, ≤ 6.0.5+9 more2018-08-20
CVE-2018-1394 [MEDIUM] CWE-79 CVE-2018-1394: Multiple IBM Rational products are vulnerable to cross-site scripting. This vulnerability allows use
Multiple IBM Rational products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138425.
cvelistv5nvd
CVE-2017-1753MEDIUMCVSS 5.4≥ 5.0.0, ≤ 5.0.2≥ 6.0.0, ≤ 6.0.5+9 more2018-08-20
CVE-2017-1753 [MEDIUM] CWE-94 CVE-2017-1753: Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject mali
Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 135655.
cvelistv5nvd
CVE-2018-1422MEDIUMCVSS 5.4≥ 5.0, ≤ 5.0.2≥ 6.0.0, ≤ 6.0.5+9 more2018-08-06
CVE-2018-1422 [MEDIUM] CWE-79 CVE-2018-1422: IBM Jazz Foundation products (IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6
IBM Jazz Foundation products (IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.5) are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID
cvelistv5nvd
CVE-2018-1529MEDIUMCVSS 5.4≥ 5.0.0, ≤ 5.0.2≥ 6.0.0, ≤ 6.0.52018-07-19
CVE-2018-1529 [MEDIUM] CWE-79 CVE-2018-1529: IBM Rational DOORS Next Generation 5.0 through 5.0.2, 6.0 through 6.0.5 and IBM Rational Requirement
IBM Rational DOORS Next Generation 5.0 through 5.0.2, 6.0 through 6.0.5 and IBM Rational Requirements Composer 5.0 through 5.0.2 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted
nvd
CVE-2018-1423MEDIUMCVSS 6.5≥ 5.0, ≤ 5.0.2≥ 6.0.0, ≤ 6.0.5+9 more2018-07-10
CVE-2018-1423 [MEDIUM] CWE-200 CVE-2018-1423: IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that
IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in further attacks against the system. IBM X-Force ID: 139026.
cvelistv5nvd
CVE-2018-1492MEDIUMCVSS 6.8≥ 5.0, ≤ 5.0.2≥ 6.0.0, ≤ 6.0.5+9 more2018-07-10
CVE-2018-1492 [MEDIUM] CWE-384 CVE-2018-1492: IBM Jazz Foundation products could allow a user with physical access to the system to log in as anot
IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977.
cvelistv5nvd
CVE-2017-1509MEDIUMCVSS 4.3≥ 6.0.0, ≤ 6.0.5v5.0.1+7 more2018-07-06
CVE-2017-1509 [MEDIUM] CWE-200 CVE-2017-1509: IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from
IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from a stack trace that could be used to aid future attacks. IBM X-Force ID: 129719.
cvelistv5nvd
CVE-2018-1494MEDIUMCVSS 5.4v5.0v5.0.1+8 more2018-07-06
CVE-2018-1494 [MEDIUM] CWE-79 CVE-2018-1494: IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-s
IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141097.
cvelistv5nvd
CVE-2017-1237MEDIUMCVSS 5.4≥ 6.0.0, ≤ 6.0.5v5.0.1+7 more2018-07-06
CVE-2017-1237 [MEDIUM] CWE-79 CVE-2017-1237: IBM Jazz based applications are vulnerable to cross-site scripting. This vulnerability allows users
IBM Jazz based applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124355.
cvelistv5nvd
CVE-2017-1488MEDIUMCVSS 5.3≥ 6.0.0, ≤ 6.0.5v5.0.1+7 more2018-07-06
CVE-2017-1488 [MEDIUM] CWE-200 CVE-2017-1488: An undisclosed vulnerability in Jazz common products exists with potential for information disclosur
An undisclosed vulnerability in Jazz common products exists with potential for information disclosure. IBM X-Force ID: 128627.
cvelistv5nvd
CVE-2017-1559MEDIUMCVSS 4.3≥ 6.0.0, ≤ 6.0.5v5.0.1+7 more2018-07-06
CVE-2017-1559 [MEDIUM] CWE-200 CVE-2017-1559: Multiple IBM Rational products could disclose sensitive information by an attacker that intercepts v
Multiple IBM Rational products could disclose sensitive information by an attacker that intercepts vulnerable requests. IBM X-Force ID: 131758.
cvelistv5nvd
CVE-2018-1507MEDIUMCVSS 5.4v6.0.52018-06-27
CVE-2018-1507 [MEDIUM] CWE-79 CVE-2018-1507: IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability
IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141415.
cvelistv5nvd
CVE-2017-1725MEDIUMCVSS 4.3≥ 5.0, ≤ 5.0.2≥ 6.0, ≤ 6.0.5+9 more2018-04-24
CVE-2017-1725 [MEDIUM] CWE-200 CVE-2017-1725: IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Manageme
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM) contain
cvelistv5nvd
CVE-2017-1700MEDIUMCVSS 6.5≥ 5.0, ≤ 5.0.2≥ 6.0, ≤ 6.0.5+9 more2018-04-24
CVE-2017-1700 [MEDIUM] CWE-863 CVE-2017-1700: IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Manageme
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM) could a
cvelistv5nvd
CVE-2017-1734MEDIUMCVSS 4.3≥ 5.0, ≤ 5.0.2≥ 6.0, ≤ 6.0.5+9 more2018-04-24
CVE-2017-1734 [MEDIUM] CWE-200 CVE-2017-1734: IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Manageme
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM) stores
cvelistv5nvd
CVE-2017-1790MEDIUMCVSS 5.4v6.0.0v6.0.1+8 more2018-04-12
CVE-2017-1790 [MEDIUM] CWE-79 CVE-2017-1790: IBM DOORS Next Generation (DNG/RRC) 5.0, 5.0.1, 5.0.2, and 6.0 through 6.0.5 is vulnerable to cross-
IBM DOORS Next Generation (DNG/RRC) 5.0, 5.0.1, 5.0.2, and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137035.
cvelistv5nvd
CVE-2017-1524MEDIUMCVSS 4.3≥ 4.0.1, ≤ 4.0.7≥ 6.0.0, ≤ 6.0.5+3 more2018-03-23
CVE-2017-1524 [MEDIUM] CWE-200 CVE-2017-1524: IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an aut
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request that could be used to aid future attacks. IBM X-Force ID: 129970.
nvd
CVE-2017-1629MEDIUMCVSS 5.4≥ 4.0.1, ≤ 4.0.7≥ 5.0, ≤ 5.0.2+1 more2018-03-23
CVE-2017-1629 [MEDIUM] CWE-79 CVE-2017-1629: IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to c
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133127.
nvd
CVE-2017-1602MEDIUMCVSS 4.3≥ 4.0.1, ≤ 4.0.7≥ 6.0.0, ≤ 6.0.5+3 more2018-03-23
CVE-2017-1602 [MEDIUM] CWE-552 CVE-2017-1602: IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticate
IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially crafted URL. IBM X-Force ID: 132625.
nvd
CVE-2017-1655MEDIUMCVSS 5.4≥ 4.0.1, ≤ 4.0.7≥ 5.0, ≤ 5.0.2+1 more2018-03-23
CVE-2017-1655 [MEDIUM] CWE-79 CVE-2017-1655: IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to c
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133379.
nvd