cbcvebase.

Ibm Rational Quality Manager vulnerabilities

201 known vulnerabilities affecting ibm/rational_quality_manager.

Total CVEs
201
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM182LOW12

Vulnerabilities

Page 2 of 11
CVE-2021-20345P4MEDIUMCVSS 5.4v6.0.6v6.0.6.12021-06-02
CVE-2021-20345 [MEDIUM] CWE-918 CVE-2021-20345: IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194594.
nvd
CVE-2021-20348P4MEDIUMCVSS 5.4v6.0.6v6.0.6.12021-06-02
CVE-2021-20348 [MEDIUM] CWE-918 CVE-2021-20348: IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-ForceID: 194597.
nvd
CVE-2015-0113P4MEDIUMCVSS 5.0v4.0v4.0.0.1+10 more2015-04-27
CVE-2015-0113 [MEDIUM] CWE-200 CVE-2015-0113: The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Requirements Composer 4.0 through 4.0.7, Rational DOORS Next Generation 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Eng
nvd
CVE-2014-6129P4MEDIUMCVSS 5.5v2.0v2.0.0.1+23 more2015-03-18
CVE-2014-6129 [MEDIUM] CWE-264 CVE-2014-6129: IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x befo
nvd
CVE-2017-1248P4MEDIUMCVSS 6.1≥ 5.0, ≤ 5.0.2≥ 6.0, ≤ 6.0.5+7 more2018-07-06
CVE-2017-1248 [MEDIUM] CWE-94 CVE-2017-1248: IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote att IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124628.
nvd
CVE-2016-3014P4MEDIUMCVSS 5.4v4.0.0v4.0.1+9 more2016-11-30
CVE-2016-3014 [MEDIUM] CWE-79 CVE-2016-3014: Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 befo Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Quality Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Team Concert 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational DOORS Next Generation 4.0 before 4.0.7 iFix11 a
nvd
CVE-2017-1239P4MEDIUMCVSS 5.3≥ 5.0, ≤ 5.0.2≥ 6.0, ≤ 6.0.5+7 more2018-07-06
CVE-2017-1239 [MEDIUM] CWE-200 CVE-2017-1239: IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 could reveal sensitive information in HTTP 500 IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID: 124357.
nvd
CVE-2017-1488P4MEDIUMCVSS 5.3≥ 6.0.0, ≤ 6.0.5v5.0.1+7 more2018-07-06
CVE-2017-1488 [MEDIUM] CWE-200 CVE-2017-1488: An undisclosed vulnerability in Jazz common products exists with potential for information disclosur An undisclosed vulnerability in Jazz common products exists with potential for information disclosure. IBM X-Force ID: 128627.
nvd
CVE-2018-1549P4MEDIUMCVSS 5.4≥ 5.0, ≤ 5.0.2≥ 6.0, ≤ 6.0.5+9 more2018-07-10
CVE-2018-1549 [MEDIUM] CWE-74 CVE-2018-1549: IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poison
nvd
CVE-2017-1242P4MEDIUMCVSS 5.4≥ 5.0, ≤ 5.0.2≥ 6.0, ≤ 6.0.5+7 more2018-07-06
CVE-2017-1242 [MEDIUM] CWE-94 CVE-2017-1242: IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote att IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124524.
nvd
CVE-2017-1329P4MEDIUMCVSS 5.4≥ 5.0, ≤ 5.0.2≥ 6.0, ≤ 6.0.5+7 more2018-07-06
CVE-2017-1329 [MEDIUM] CWE-94 CVE-2017-1329: IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote att IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 126231.
nvd
CVE-2020-4547P4MEDIUMCVSS 5.4v6.0.2v6.0.6+1 more2021-01-27
CVE-2020-4547 [MEDIUM] CWE-1021 CVE-2020-4547: IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the vict IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 183315.
nvd
CVE-2016-9973P4MEDIUMCVSS 5.4v4.0v4.0.1+13 more2017-06-13
CVE-2016-9973 [MEDIUM] CWE-79 CVE-2016-9973: IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120209.
nvd
CVE-2014-3092P4MEDIUMCVSS 5.0v2.0v2.0.0.1+21 more2014-09-12
CVE-2014-3092 [MEDIUM] CWE-200 CVE-2014-3092: IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manag IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting
nvd
CVE-2015-7453P4MEDIUMCVSS 6.1≥ 3.0, ≤ 3.0.1.6≥ 4.0, ≤ 4.0.7+5 more2018-03-15
CVE-2015-7453 [MEDIUM] CWE-79 CVE-2015-7453: Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3. Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and
nvd
CVE-2017-1653P4MEDIUMCVSS 5.4≥ 6.0, ≤ 6.0.42018-01-26
CVE-2017-1653 [MEDIUM] CWE-79 CVE-2017-1653: IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 6.0.x) is vulnerable to cross-s IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 6.0.x) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133268.
nvd
CVE-2016-2926P4MEDIUMCVSS 5.4v3.0.1.6v4.0.0+13 more2016-11-25
CVE-2016-2926 [MEDIUM] CWE-79 CVE-2016-2926: Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 befo Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Team Concert 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 b
nvd
CVE-2018-1916P4MEDIUMCVSS 5.4≥ 5.0, ≤ 6.0.62019-03-14
CVE-2018-1916 [MEDIUM] CWE-79 CVE-2018-1916: IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152740.
nvd
CVE-2018-1952P4MEDIUMCVSS 5.4≥ 5.0, ≤ 6.0.62019-03-14
CVE-2018-1952 [MEDIUM] CWE-79 CVE-2018-1952: IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153495.
nvd
CVE-2017-1753P4MEDIUMCVSS 5.4≥ 5.0.0, ≤ 5.0.2≥ 6.0.0, ≤ 6.0.5+9 more2018-08-20
CVE-2017-1753 [MEDIUM] CWE-94 CVE-2017-1753: Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject mali Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 135655.
nvd
Ibm Rational Quality Manager vulnerabilities | cvebase