Ibm Rhapsody Design Manager vulnerabilities
14 known vulnerabilities affecting ibm/rhapsody_design_manager.
Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM12LOW2
Vulnerabilities
Page 1 of 1
CVE-2021-20357MEDIUMCVSS 5.4v6.0.2v6.0.6+2 more2021-01-27
CVE-2021-20357 [MEDIUM] CWE-79 CVE-2021-20357: IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194963.
nvd
CVE-2020-4524MEDIUMCVSS 5.4v6.0.2v6.0.6+2 more2021-01-27
CVE-2020-4524 [MEDIUM] CWE-79 CVE-2020-4524: IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182434.
nvd
CVE-2020-4865MEDIUMCVSS 5.4v6.0.2v6.0.6+2 more2021-01-27
CVE-2020-4865 [MEDIUM] CWE-79 CVE-2020-4865: IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741.
nvd
CVE-2020-4547MEDIUMCVSS 5.4v6.0.2v6.0.6+2 more2021-01-27
CVE-2020-4547 [MEDIUM] CWE-1021 CVE-2020-4547: IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the vict
IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 183315.
nvd
CVE-2020-4855MEDIUMCVSS 5.4v6.0.2v6.0.6+2 more2021-01-27
CVE-2020-4855 [MEDIUM] CWE-79 CVE-2020-4855: IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190457.
nvd
CVE-2019-4748MEDIUMCVSS 5.4v6.0.2v6.0.6+1 more2020-07-16
CVE-2019-4748 [MEDIUM] CWE-79 CVE-2019-4748: IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability a
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173174.
nvd
CVE-2017-1287MEDIUMCVSS 5.4v5.0v5.0.1+5 more2017-07-24
CVE-2017-1287 [MEDIUM] CWE-601 CVE-2017-1287: IBM Rhapsody DM 5.0 and 6.0 could allow a remote attacker to conduct phishing attacks, using an open
IBM Rhapsody DM 5.0 and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow th
nvd
CVE-2017-1249MEDIUMCVSS 5.4v5.0v5.0.1+5 more2017-07-24
CVE-2017-1249 [MEDIUM] CWE-79 CVE-2017-1249: IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users t
IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-8975MEDIUMCVSS 5.4v5.0v5.0.1+5 more2017-07-24
CVE-2016-8975 [MEDIUM] CWE-79 CVE-2016-8975: IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users t
IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118912.
nvd
CVE-2015-0112MEDIUMCVSS 4.0v3.0.0v3.0.0.1+11 more2015-06-07
CVE-2015-0112 [MEDIUM] CVE-2015-0112: Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1,
Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1, 4.x before 4.0.7 IF5, and 5.x before 5.0.2 IF4; Rational Quality Manager (RQM) 2.0 through 2.0.1, 3.0 through 3.0.1.6, 4.0 through 4.0.7, and 5.0 through 5.0.2; Rational Team Concert (RTC) 2.0 through 2.0.0.2, 3.x before 3.0.1.6 IF6, 4.x before 4.0.7 IF5, and 5.
nvd
CVE-2014-0948MEDIUMCVSS 6.0v3.0.0v3.0.0.1+8 more2014-07-30
CVE-2014-0948 [MEDIUM] CVE-2014-0948: Unspecified vulnerability in IBM Rational Software Architect Design Manager and Rational Rhapsody De
Unspecified vulnerability in IBM Rational Software Architect Design Manager and Rational Rhapsody Design Manager 3.x and 4.x before 4.0.7 allows remote authenticated users to execute arbitrary code via a crafted ZIP archive.
nvd
CVE-2013-5459MEDIUMCVSS 5.5v3.0.0v3.0.0.1+7 more2014-04-21
CVE-2013-5459 [MEDIUM] CVE-2013-5459: Unspecified vulnerability in IBM Rational Software Architect (RSA) Design Manager and Rational Rhaps
Unspecified vulnerability in IBM Rational Software Architect (RSA) Design Manager and Rational Rhapsody Design Manager 3.x through 3.0.1 and 4.x before 4.0.6 allows remote authenticated users to modify data by leveraging improper parameter checking.
nvd
CVE-2013-3042LOWCVSS 2.1v3.0.0v3.0.0.1+6 more2013-12-14
CVE-2013-3042 [LOW] CWE-22 CVE-2013-3042: Directory traversal vulnerability in the server in IBM Rational Software Architect Design Manager an
Directory traversal vulnerability in the server in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files.
nvd
CVE-2013-3043LOWCVSS 2.1v3.0.0v3.0.0.1+6 more2013-12-14
CVE-2013-3043 [LOW] CWE-22 CVE-2013-3043: Directory traversal vulnerability in the client in IBM Rational Software Architect Design Manager an
Directory traversal vulnerability in the client in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files.
nvd