cbcvebase.

Ibm Rational Requirements Composer vulnerabilities

38 known vulnerabilities affecting ibm/rational_requirements_composer.

Total CVEs
38
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM27LOW9

Vulnerabilities

Page 2 of 2
CVE-2013-3039P4MEDIUMCVSS 5.4≤ 4.0.3v4.0.0+2 more2013-09-12
CVE-2013-3039 [MEDIUM] CWE-287 CVE-2013-3039: IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors.
nvd
CVE-2015-7471P4MEDIUMCVSS 4.8≥ 3.0, ≤ 3.0.1.6≥ 4.0, ≤ 4.0.72018-03-15
CVE-2015-7471 [MEDIUM] CWE-79 CVE-2015-7471: Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3. Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and
nvd
CVE-2013-3038P4MEDIUMCVSS 5.4≤ 4.0.3v4.0.0+2 more2013-09-12
CVE-2013-3038 [MEDIUM] CWE-255 CVE-2013-3038: Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for rem Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for remote attackers to discover credentials via unknown vectors.
nvd
CVE-2013-3036P4MEDIUMCVSS 4.9≤ 4.0.3v4.0.0+2 more2013-09-12
CVE-2013-3036 [MEDIUM] CWE-20 CVE-2013-3036: Open redirect vulnerability in IBM Rational Requirements Composer before 4.0.4 allows remote authent Open redirect vulnerability in IBM Rational Requirements Composer before 4.0.4 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
nvd
CVE-2016-6060P4MEDIUMCVSS 4.3v4.0.1v4.0.2+5 more2017-02-15
CVE-2016-6060 [MEDIUM] CWE-200 CVE-2016-6060: An undisclosed vulnerability in IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 could allow a J An undisclosed vulnerability in IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 could allow a JazzGuest user to see project names. IBM Reference #: 1995547.
nvd
CVE-2014-0845P4MEDIUMCVSS 4.9v3.0.1v3.0.1.1+13 more2014-03-04
CVE-2014-0845 [MEDIUM] CWE-20 CVE-2014-0845: Open redirect vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x b Open redirect vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
nvd
CVE-2015-1971P4MEDIUMCVSS 4.3v2.0v2.0.0.1+21 more2016-01-03
CVE-2015-1971 [MEDIUM] CVE-2015-1971: Unspecified vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifec Unspecified vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF8, and 5.x before 5.0.2 IF10; Rational Team Concert (RTC) 2.x and 3.x before 3.0.1.6 IF7, 4.x before
nvd
CVE-2016-9748P4MEDIUMCVSS 4.3v4.0.72017-02-08
CVE-2016-9748 [MEDIUM] CWE-200 CVE-2016-9748: IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response mes IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system.
nvd
CVE-2014-0844P4LOWCVSS 3.5v3.0.1v3.0.1.1+13 more2014-03-04
CVE-2014-0844 [LOW] CVE-2014-0844: Unspecified vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x bef Unspecified vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to read arbitrary data via unknown vectors.
nvd
CVE-2013-5404P4LOWCVSS 3.5v2.0v2.0.0.1+16 more2013-12-10
CVE-2013-5404 [LOW] CWE-79 CVE-2013-5404: Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manage Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other products, allows remote authenticated users to inject arbitrary web script or HTML via vectors involvin
nvd
CVE-2013-3037P4MEDIUMCVSS 4.4≤ 4.0.3v4.0.0+2 more2013-09-12
CVE-2013-3037 [MEDIUM] CWE-264 CVE-2013-3037: Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for loc Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for local users to gain privileges via unknown vectors.
nvd
CVE-2015-0121P4LOWCVSS 3.7v3.0v3.0.1+17 more2015-05-30
CVE-2015-0121 [LOW] CVE-2015-0121: IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next Generation (RDNG) 4.0 through 4.0.7 and 5.0 through 5.0.2, when LTPA single sign on is used with WebSphere Application Server, do not terminate a Requirements Management (RM) session upon LTPA token expiration, which allows remote attackers to obtain access by le
nvd
CVE-2015-0130P4LOWCVSS 3.5v4.0.0v4.0.0.1+8 more2015-07-20
CVE-2015-0130 [LOW] CWE-79 CVE-2015-0130: Cross-site scripting (XSS) vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Coll Cross-site scripting (XSS) vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Quality Manager (RQM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Team Concert (RTC) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Requirement
nvd
CVE-2015-0125P4LOWCVSS 3.5v4.0.0v4.0.0.1+8 more2015-03-18
CVE-2015-0125 [LOW] CWE-79 CVE-2015-0125: Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 4.x before 4.0.7 iFix3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2015-4962P4LOWCVSS 3.5v2.0v2.0.0.1+21 more2016-01-03
CVE-2015-4962 [LOW] CWE-200 CVE-2015-4962: Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Team Concert (RTC) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7
nvd
CVE-2014-0846P4LOWCVSS 3.5v3.0.1v3.0.1.1+13 more2014-03-04
CVE-2014-0846 [LOW] CWE-79 CVE-2014-0846: Cross-site scripting (XSS) vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iF Cross-site scripting (XSS) vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2015-4946P4LOWCVSS 3.3v2.0v2.0.0.1+21 more2016-01-03
CVE-2015-4946 [LOW] CWE-264 CVE-2015-4946: Rational LifeCycle Project Administration in Jazz Team Server in IBM Rational Collaborative Lifecycl Rational LifeCycle Project Administration in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Team Concert (RTC) 3.x before 3.0
nvd
CVE-2015-7449P4LOWCVSS 3.3≥ 4.0.0, ≤ 4.0.72018-03-20
CVE-2015-7449 [LOW] CWE-200 CVE-2015-7449: IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Manager (RQM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Team Concert (RTC) 4.0.x before 4.0.7 iFix10, 5.0.x bef
nvd
Ibm Rational Requirements Composer vulnerabilities | cvebase