cbcvebase.

Ibm Rational Requirements Composer vulnerabilities

38 known vulnerabilities affecting ibm/rational_requirements_composer.

Total CVEs
38
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM27LOW9

Vulnerabilities

Page 1 of 2
CVE-2015-7440P3HIGHCVSS 7.8≥ 3.0, ≤ 3.0.1.6≥ 4.0, ≤ 4.0.72018-03-15
CVE-2015-7440 [HIGH] CWE-264 CVE-2015-7440: IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0. IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Team Conc
nvd
CVE-2015-0132P4HIGHCVSS 7.8v2.0v2.0.0.1+22 more2015-03-18
CVE-2015-0132 [HIGH] CVE-2015-0132: The XML parser in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and The XML parser in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5 and 4.x before 4.0.7 iFix3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document cont
nvd
CVE-2015-1928P4MEDIUMCVSS 6.8v2.0v2.0.0.1+21 more2016-01-02
CVE-2015-1928 [MEDIUM] CWE-20 CVE-2015-1928: Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.x before 6.0.0 IF4; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.0 before 6.0.0 IF4; Rational Team Concert (RTC) 3.x before 3.0.1.6 IF7, 4.x
nvd
CVE-2016-0219P4MEDIUMCVSS 6.5v3.0v3.0.1+14 more2018-01-16
CVE-2016-0219 [MEDIUM] CWE-611 CVE-2016-0219: XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interi XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote authenticated users to cause a denial of service via crafted XML data. IBM X-Force ID: 109693.
nvd
CVE-2015-0113P4MEDIUMCVSS 5.0v4.0.0v4.0.0.1+8 more2015-04-27
CVE-2015-0113 [MEDIUM] CWE-200 CVE-2015-0113: The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Requirements Composer 4.0 through 4.0.7, Rational DOORS Next Generation 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Eng
nvd
CVE-2014-6129P4MEDIUMCVSS 5.5v2.0v2.0.0.1+11 more2015-03-18
CVE-2014-6129 [MEDIUM] CWE-264 CVE-2014-6129: IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x befo
nvd
CVE-2014-3092P4MEDIUMCVSS 5.0v2.0v2.0.0.1+21 more2014-09-12
CVE-2014-3092 [MEDIUM] CWE-200 CVE-2014-3092: IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manag IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting
nvd
CVE-2015-7453P4MEDIUMCVSS 6.1≥ 3.0, ≤ 3.0.1.6≥ 4.0, ≤ 4.0.72018-03-15
CVE-2015-7453 [MEDIUM] CWE-79 CVE-2015-7453: Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3. Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and
nvd
CVE-2017-1278P4MEDIUMCVSS 5.4v4.0.1v4.0.2+5 more2017-06-12
CVE-2017-1278 [MEDIUM] CWE-79 CVE-2017-1278: IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to HTML injection. A remote attac IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124756.
nvd
CVE-2018-1529P4MEDIUMCVSS 5.4≥ 5.0.0, ≤ 5.0.22018-07-19
CVE-2018-1529 [MEDIUM] CWE-79 CVE-2018-1529: IBM Rational DOORS Next Generation 5.0 through 5.0.2, 6.0 through 6.0.5 and IBM Rational Requirement IBM Rational DOORS Next Generation 5.0 through 5.0.2, 6.0 through 6.0.5 and IBM Rational Requirements Composer 5.0 through 5.0.2 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted
nvd
CVE-2017-1338P4MEDIUMCVSS 5.4v4.0.1v4.0.2+8 more2017-08-18
CVE-2017-1338 [MEDIUM] CWE-79 CVE-2017-1338: IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vu IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126246.
nvd
CVE-2017-1276P4MEDIUMCVSS 5.4v4.0.1v4.0.2+5 more2017-06-12
CVE-2017-1276 [MEDIUM] CWE-79 CVE-2017-1276: IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vul IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124751.
nvd
CVE-2017-1247P4MEDIUMCVSS 5.4v4.0.1v4.0.2+5 more2017-06-12
CVE-2017-1247 [MEDIUM] CWE-79 CVE-2017-1247: IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vul IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124627.
nvd
CVE-2017-1546P4MEDIUMCVSS 5.4v4.0v4.0.7+3 more2017-12-13
CVE-2017-1546 [MEDIUM] CWE-79 CVE-2017-1546: IBM DOORS Next Generation (DNG/RRC) 4.07, 5.0, and 6.0 is vulnerable to cross-site scripting. This v IBM DOORS Next Generation (DNG/RRC) 4.07, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130915.
nvd
CVE-2017-1790P4MEDIUMCVSS 5.4v5.0v5.0.1+1 more2018-04-12
CVE-2017-1790 [MEDIUM] CWE-79 CVE-2017-1790: IBM DOORS Next Generation (DNG/RRC) 5.0, 5.0.1, 5.0.2, and 6.0 through 6.0.5 is vulnerable to cross- IBM DOORS Next Generation (DNG/RRC) 5.0, 5.0.1, 5.0.2, and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137035.
nvd
CVE-2017-1127P4MEDIUMCVSS 5.4v4.0v4.0.0+9 more2017-02-08
CVE-2017-1127 [MEDIUM] CWE-79 CVE-2017-1127: IBM Rational DOORS Next Generation 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vuln IBM Rational DOORS Next Generation 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2017-1128P4MEDIUMCVSS 5.4v4.0v4.0.0+9 more2017-02-08
CVE-2017-1128 [MEDIUM] CWE-79 CVE-2017-1128: IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vul IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-6055P4MEDIUMCVSS 5.4v4.0.1v4.0.2+5 more2017-02-23
CVE-2016-6055 [MEDIUM] CWE-79 CVE-2016-6055: IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vul IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1995515.
nvd
CVE-2015-0112P4MEDIUMCVSS 4.0v2.0v2.0.0.1+23 more2015-06-07
CVE-2015-0112 [MEDIUM] CVE-2015-0112: Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1, Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1, 4.x before 4.0.7 IF5, and 5.x before 5.0.2 IF4; Rational Quality Manager (RQM) 2.0 through 2.0.1, 3.0 through 3.0.1.6, 4.0 through 4.0.7, and 5.0 through 5.0.2; Rational Team Concert (RTC) 2.0 through 2.0.0.2, 3.x before 3.0.1.6 IF6, 4.x before 4.0.7 IF5, and 5.
nvd
CVE-2014-6131P4MEDIUMCVSS 4.0v2.0v2.0.0.1+11 more2015-03-18
CVE-2014-6131 [MEDIUM] CWE-200 CVE-2014-6131: IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x befo
nvd