Ibm Tririga Application Platform vulnerabilities
47 known vulnerabilities affecting ibm/tririga_application_platform.
Total CVEs
47
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM27LOW7
Vulnerabilities
Page 3 of 3
CVE-2014-8893P4LOWCVSS 3.5v3.2.1v3.3.2.0+5 more2015-01-29
CVE-2014-8893 [LOW] CWE-79 CVE-2014-8893: Multiple cross-site scripting (XSS) vulnerabilities in (1) mainpage.jsp and (2) GetImageServlet.img
Multiple cross-site scripting (XSS) vulnerabilities in (1) mainpage.jsp and (2) GetImageServlet.img in IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-4836P4LOWCVSS 3.5v3.2v3.2.1+8 more2014-10-19
CVE-2014-4836 [LOW] CWE-79 CVE-2014-4836: Cross-site scripting (XSS) vulnerability in breakOutWithName.jsp in IBM TRIRIGA Application Platform
Cross-site scripting (XSS) vulnerability in breakOutWithName.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-4837P4LOWCVSS 3.5v3.2v3.2.1+8 more2014-10-19
CVE-2014-4837 [LOW] CWE-79 CVE-2014-4837: Cross-site scripting (XSS) vulnerability in NewDocument.jsp in IBM TRIRIGA Application Platform 3.2
Cross-site scripting (XSS) vulnerability in NewDocument.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-4838P4LOWCVSS 3.5v3.2v3.2.1+8 more2014-10-19
CVE-2014-4838 [LOW] CWE-79 CVE-2014-4838: Cross-site scripting (XSS) vulnerability in GanttProjectSchedulerPopup.jsp in IBM TRIRIGA Applicatio
Cross-site scripting (XSS) vulnerability in GanttProjectSchedulerPopup.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2013-4003P4LOWCVSS 3.5≤ 3.3.0.1v2.1+8 more2013-08-29
CVE-2013-4003 [LOW] CWE-79 CVE-2013-4003: Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x
Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3.1.1, and 8, allow remote authenticated users to inject arbitrary web script or HTML via (1) unspecified input to WebProcess.srv, (2) unspecified input to html/en/default/actionHandler/queryHandler.jsp, or (3) unspecified input in a portalSectionId
nvd
CVE-2013-6726P4LOWCVSS 3.5v3.2v3.2.1+4 more2014-05-07
CVE-2013-6726 [LOW] CWE-79 CVE-2013-6726: Multiple cross-site scripting (XSS) vulnerabilities in WebProcess.srv in IBM TRIRIGA Application Pla
Multiple cross-site scripting (XSS) vulnerabilities in WebProcess.srv in IBM TRIRIGA Application Platform 3.2.x and 3.3.x before 3.3.1.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2019-4207P4LOWCVSS 3.3≥ 3.5.3.0, < 3.5.3.6≥ 3.6.0.0, < 3.6.0.3+2 more2019-05-07
CVE-2019-4207 [LOW] CVE-2019-4207: IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 may disclose sensitive information only available t
IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 may disclose sensitive information only available to a local user that could be used in further attacks against the system. IBM X-Force ID: 159148.
nvd
← Previous3 / 3