cbcvebase.

Ibm Tririga Application Platform vulnerabilities

47 known vulnerabilities affecting ibm/tririga_application_platform.

Total CVEs
47
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM27LOW7

Vulnerabilities

Page 2 of 3
CVE-2012-5950P4MEDIUMCVSS 6.8v2.1v2.5+7 more2013-04-23
CVE-2012-5950 [MEDIUM] CWE-352 CVE-2012-5950: Multiple cross-site request forgery (CSRF) vulnerabilities in IBM TRIRIGA Application Platform 2.x a Multiple cross-site request forgery (CSRF) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to hijack the authentication of arbitrary users for requests that modify data records via vectors involving (1) the html/en/default/ directory or (2) sqa/html/en/default/process/comm/saveProps.jsp.
nvd
CVE-2017-1465P4MEDIUMCVSS 5.4v3.3.0.0v3.3.0.1+42 more2017-12-07
CVE-2017-1465 [MEDIUM] CWE-79 CVE-2017-1465: IBM TRIRIGA 3.2, 3.3, 3.4, and 3.5 could allow a remote attacker to hijack the clicking action of th IBM TRIRIGA 3.2, 3.3, 3.4, and 3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 128464.
nvd
CVE-2016-6000P4MEDIUMCVSS 6.1v3.3.0.0v3.3.0.1+26 more2017-02-01
CVE-2016-6000 [MEDIUM] CWE-79 CVE-2016-6000: IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows us IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-0344P4MEDIUMCVSS 5.4≥ 3.3.0.0, < 3.3.2.6≥ 3.4.0.0, ≤ 3.4.2.3+1 more2018-02-21
CVE-2016-0344 [MEDIUM] CWE-79 CVE-2016-0344: Cross-site scripting (XSS) vulnerability in the My Reports component in IBM TRIRIGA Application Plat Cross-site scripting (XSS) vulnerability in the My Reports component in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111785.
nvd
CVE-2017-1372P4MEDIUMCVSS 5.4v3.3.0.0v3.3.0.1+40 more2017-07-21
CVE-2017-1372 [MEDIUM] CWE-79 CVE-2017-1372: IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulne IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126865.
nvd
CVE-2016-9737P4MEDIUMCVSS 5.4v3.3.0.0v3.3.0.1+24 more2017-03-27
CVE-2016-9737 [MEDIUM] CWE-79 CVE-2016-9737: IBM TRIRIGA 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users IBM TRIRIGA 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1996200.
nvd
CVE-2022-43914P4MEDIUMCVSS 5.4≥ 4.0, < 4.0.3v4.02023-04-07
CVE-2022-43914 [MEDIUM] CWE-79 CVE-2022-43914: IBM TRIRIGA Application Platform 4.0 is vulnerable to cross-site scripting. This vulnerability allow IBM TRIRIGA Application Platform 4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 241036.
nvd
CVE-2020-4868P4MEDIUMCVSS 5.3≥ 3.0, < 4.5v3.0, 4.0, 4.42023-07-31
CVE-2020-4868 [MEDIUM] CWE-209 CVE-2020-4868: IBM TRIRIGA 3.0, 4.0, and 4.4 could allow a remote attacker to obtain sensitive information when a d IBM TRIRIGA 3.0, 4.0, and 4.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190744.
nvd
CVE-2014-4839P4MEDIUMCVSS 6.0v3.2v3.3.0.0+6 more2014-10-29
CVE-2014-4839 [MEDIUM] CWE-352 CVE-2014-4839: Cross-site request forgery (CSRF) vulnerability in birtviewer.query in IBM TRIRIGA Application Platf Cross-site request forgery (CSRF) vulnerability in birtviewer.query in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
nvd
CVE-2016-0387P4MEDIUMCVSS 5.4v3.3.0.0v3.3.0.1+21 more2016-07-02
CVE-2016-0387 [MEDIUM] CWE-79 CVE-2016-0387: Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2883.
nvd
CVE-2016-2883P4MEDIUMCVSS 5.4v3.3.0.0v3.3.0.1+20 more2016-07-02
CVE-2016-2883 [MEDIUM] CVE-2016-2883: Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0387.
nvd
CVE-2016-5980P4MEDIUMCVSS 5.4v3.3.0.0v3.3.0.1+26 more2017-02-01
CVE-2016-5980 [MEDIUM] CWE-79 CVE-2016-5980: IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows us IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2018-2008P4MEDIUMCVSS 4.3≥ 3.5.3.0, < 3.5.3.6≥ 3.6.0.0, < 3.6.0.3+2 more2019-05-07
CVE-2018-2008 [MEDIUM] CWE-200 CVE-2018-2008: IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 could disclose sensitive information to an authenti IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 could disclose sensitive information to an authenticated user that could aid in further attacks against the system. IBM X-Force ID: 155146.
nvd
CVE-2014-8894P4MEDIUMCVSS 4.9v3.2.1v3.3.2.0+5 more2015-01-29
CVE-2014-8894 [MEDIUM] CVE-2014-8894: Open redirect vulnerability in IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3 Open redirect vulnerability in IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the out parameter.
nvd
CVE-2016-0345P4MEDIUMCVSS 4.3≥ 3.3.0.0, < 3.3.2.6≥ 3.4.0.0, < 3.4.2.3+1 more2018-02-21
CVE-2016-0345 [MEDIUM] CWE-200 CVE-2016-0345: IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allo IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain the installation path via vectors involving Birt report rendering. IBM X-Force ID: 111786.
nvd
CVE-2012-5948P4MEDIUMCVSS 4.3v2.1v2.5+7 more2013-04-23
CVE-2012-5948 [MEDIUM] CWE-79 CVE-2012-5948: Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) WebProcess.srv, (2) the html/en/default/ directory, (3) Widget/resource, (4) birt/frameset, or (5) ganttlib/gantt-jws.jnlp.
nvd
CVE-2016-2882P4MEDIUMCVSS 4.3v3.3.0.0v3.3.0.1+20 more2016-07-02
CVE-2016-2882 [MEDIUM] CWE-200 CVE-2016-2882: IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allo IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to obtain sensitive information by reading HTTP responses.
nvd
CVE-2017-1171P4MEDIUMCVSS 4.3v3.3.0.0v3.3.0.1+31 more2017-03-31
CVE-2017-1171 [MEDIUM] CVE-2017-1171: The IBM TRIRIGA Application Platform 3.3, 3,4, and 3,5 contain a vulnerability that could allow an a The IBM TRIRIGA Application Platform 3.3, 3,4, and 3,5 contain a vulnerability that could allow an authenticated user to execute Application actions they do not have access to. IBM Reference #: 2001083.
nvd
CVE-2012-5949P4MEDIUMCVSS 4.3v2.1v2.5+7 more2013-04-23
CVE-2012-5949 [MEDIUM] CWE-79 CVE-2012-5949: Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject content, and conduct phishing attacks, via vectors involving (1) the html/en/default/ directory, (2) birt/frameset, (3) WebProcess.srv, (4) sqa/html/en/default/reportTemplate/reportTemplateOrderCols.jsp,
nvd
CVE-2016-0343P4MEDIUMCVSS 4.3≥ 3.3.0.0, < 3.3.2.6≥ 3.4.0.0, < 3.4.2.3+1 more2018-02-21
CVE-2016-0343 [MEDIUM] CWE-200 CVE-2016-0343: IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allo IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 111784.
nvd
Ibm Tririga Application Platform vulnerabilities | cvebase