Ibm Rational Focal Point vulnerabilities
9 known vulnerabilities affecting ibm/rational_focal_point.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4LOW5
Vulnerabilities
Page 1 of 1
CVE-2014-0841MEDIUMCVSS 5.3v6.4v6.4.1+3 more2018-04-27
CVE-2014-0841 [MEDIUM] CWE-326 CVE-2014-0841: IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash password
IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack. IBM X-Force ID: 90704.
nvd
CVE-2014-0842MEDIUMCVSS 5.0v6.4v6.4.0.1+15 more2014-02-26
CVE-2014-0842 [MEDIUM] CWE-255 CVE-2014-0842: The account-creation functionality in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.
The account-creation functionality in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 places the new user's default password within the creation page, which allows remote attackers to obtain sensitive information by reading the HTML source code.
nvd
CVE-2014-0839MEDIUMCVSS 4.0v6.4v6.4.0.1+15 more2014-02-26
CVE-2014-0839 [MEDIUM] CWE-264 CVE-2014-0839: IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allows remote authent
IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allows remote authenticated users to modify data via vectors involving a direct object reference.
nvd
CVE-2014-0853LOWCVSS 3.5v6.4v6.4.0.1+15 more2014-02-26
CVE-2014-0853 [LOW] CWE-79 CVE-2014-0853: Multiple cross-site scripting (XSS) vulnerabilities in the (1) ForwardController and (2) AttributeEd
Multiple cross-site scripting (XSS) vulnerabilities in the (1) ForwardController and (2) AttributeEditor scripts in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-0840LOWCVSS 3.5v6.4v6.4.0.1+15 more2014-02-26
CVE-2014-0840 [LOW] CWE-79 CVE-2014-0840: Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.4.x and 6.5.x befo
Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-0843LOWCVSS 3.5v6.4v6.4.0.1+15 more2014-02-26
CVE-2014-0843 [LOW] CWE-79 CVE-2014-0843: Cross-site scripting (XSS) vulnerability in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3
Cross-site scripting (XSS) vulnerability in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allows remote authenticated users to inject arbitrary web script or HTML by uploading a file.
nvd
CVE-2013-5398LOWCVSS 3.3v6.4v6.4.1.3+6 more2013-12-18
CVE-2013-5398 [LOW] CVE-2013-5398: Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devf
Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified v
nvd
CVE-2013-5397LOWCVSS 3.3v6.4v6.4.1.3+6 more2013-12-18
CVE-2013-5397 [LOW] CVE-2013-5397: Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devf
Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified v
nvd
CVE-2013-3025MEDIUMCVSS 4.3v6.5.2v6.5.2.1+3 more2013-10-17
CVE-2013-3025 [MEDIUM] CWE-79 CVE-2013-3025: Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.5.x and 6.6.x befo
Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.5.x and 6.6.x before 6.6.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd