Ibm Rational Quality Manager vulnerabilities

201 known vulnerabilities affecting ibm/rational_quality_manager.

Total CVEs
201
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM182LOW12

Vulnerabilities

Page 10 of 11
CVE-2016-0284MEDIUMCVSS 5.4v3.0.1.6v4.0.0+13 more2016-11-24
CVE-2016-0284 [MEDIUM] CWE-611 CVE-2016-0284: The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4 The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 i
nvd
CVE-2016-2864MEDIUMCVSS 5.4v3.0.1.6v4.0.0+13 more2016-11-24
CVE-2016-2864 [MEDIUM] CWE-79 CVE-2016-2864: Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before i
nvd
CVE-2016-0273MEDIUMCVSS 5.4v3.0.1.6v4.0.0+13 more2016-11-24
CVE-2016-0273 [MEDIUM] CWE-79 CVE-2016-0273: Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before i
nvd
CVE-2016-0372LOWCVSS 3.7v3.0.1.6v4.0.0+13 more2016-11-24
CVE-2016-0372 [LOW] CWE-200 CVE-2016-0372: IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 b IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0
nvd
CVE-2016-0326HIGHCVSS 8.8v3.0.1.6v4.0+14 more2016-10-22
CVE-2016-0326 [HIGH] CWE-77 CVE-2016-0326: IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iF IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iFix17, and 6.x before 6.0.1 ifix3 allow remote authenticated users to execute arbitrary OS commands via a crafted "HTML request."
nvd
CVE-2015-1971MEDIUMCVSS 4.3v2.0v2.0.1+21 more2016-01-03
CVE-2015-1971 [MEDIUM] CVE-2015-1971: Unspecified vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifec Unspecified vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF8, and 5.x before 5.0.2 IF10; Rational Team Concert (RTC) 2.x and 3.x before 3.0.1.6 IF7, 4.x before
nvd
CVE-2015-4946LOWCVSS 3.3v2.0v2.0.1+21 more2016-01-03
CVE-2015-4946 [LOW] CWE-264 CVE-2015-4946: Rational LifeCycle Project Administration in Jazz Team Server in IBM Rational Collaborative Lifecycl Rational LifeCycle Project Administration in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Team Concert (RTC) 3.x before 3.0
nvd
CVE-2015-4962LOWCVSS 3.5v2.0v2.0.1+21 more2016-01-03
CVE-2015-4962 [LOW] CWE-200 CVE-2015-4962: Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Team Concert (RTC) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7
nvd
CVE-2015-1928MEDIUMCVSS 6.8v2.0v2.0.1+21 more2016-01-02
CVE-2015-1928 [MEDIUM] CWE-20 CVE-2015-1928: Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.x before 6.0.0 IF4; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.0 before 6.0.0 IF4; Rational Team Concert (RTC) 3.x before 3.0.1.6 IF7, 4.x
nvd
CVE-2015-0130LOWCVSS 3.5v4.0v4.0.0.1+9 more2015-07-20
CVE-2015-0130 [LOW] CWE-79 CVE-2015-0130: Cross-site scripting (XSS) vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Coll Cross-site scripting (XSS) vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Quality Manager (RQM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Team Concert (RTC) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Requirement
nvd
CVE-2015-0112MEDIUMCVSS 4.0v2.0v2.0.0.1+21 more2015-06-07
CVE-2015-0112 [MEDIUM] CVE-2015-0112: Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1, Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1, 4.x before 4.0.7 IF5, and 5.x before 5.0.2 IF4; Rational Quality Manager (RQM) 2.0 through 2.0.1, 3.0 through 3.0.1.6, 4.0 through 4.0.7, and 5.0 through 5.0.2; Rational Team Concert (RTC) 2.0 through 2.0.0.2, 3.x before 3.0.1.6 IF6, 4.x before 4.0.7 IF5, and 5.
nvd
CVE-2015-0113MEDIUMCVSS 5.0v4.0v4.0.0.1+10 more2015-04-27
CVE-2015-0113 [MEDIUM] CWE-200 CVE-2015-0113: The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Requirements Composer 4.0 through 4.0.7, Rational DOORS Next Generation 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Eng
nvd
CVE-2014-6129MEDIUMCVSS 5.5v2.0v2.0.0.1+23 more2015-03-18
CVE-2014-6129 [MEDIUM] CWE-264 CVE-2014-6129: IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x befo
nvd
CVE-2014-6131MEDIUMCVSS 4.0v2.0v2.0.0.1+23 more2015-03-18
CVE-2014-6131 [MEDIUM] CWE-200 CVE-2014-6131: IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x befo
nvd
CVE-2015-0128LOWCVSS 3.5v2.0v2.0.0.1+23 more2015-03-18
CVE-2015-0128 [LOW] CVE-2015-0128: Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x and 3.x before 3.0.1.6 Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix4, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0124.
nvd
CVE-2015-0124LOWCVSS 3.5v2.0v2.0.0.1+23 more2015-03-18
CVE-2015-0124 [LOW] CWE-79 CVE-2015-0124: Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x and 3.x before 3.0.1.6 Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix4, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0128.
nvd
CVE-2015-0129LOWCVSS 3.5v4.0v4.0.0.1+9 more2015-03-13
CVE-2015-0129 [LOW] CWE-79 CVE-2015-0129: Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager (RQM) 4.x before 4.0.7 iFix Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager (RQM) 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-6144LOWCVSS 3.5v2.0v2.0.0.1+22 more2015-03-13
CVE-2014-6144 [LOW] CWE-79 CVE-2014-6144: Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager (RQM) 2.x and 3.x before 3. Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-4801LOWCVSS 3.5v2.0v2.0.0.1+21 more2014-12-19
CVE-2014-4801 [LOW] CWE-79 CVE-2014-4801: Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x through 2.0.1.1, 3.x be Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x through 2.0.1.1, 3.x before 3.0.1.6 iFix 4, 4.x before 4.0.7 iFix 2, and 5.x before 5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-3092MEDIUMCVSS 5.0v2.0v2.0.0.1+21 more2014-09-12
CVE-2014-3092 [MEDIUM] CWE-200 CVE-2014-3092: IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manag IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting
nvd
Ibm Rational Quality Manager vulnerabilities | cvebase