Ibm Tririga Application Platform vulnerabilities
46 known vulnerabilities affecting ibm/tririga_application_platform.
Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM26LOW7
Vulnerabilities
Page 3 of 3
CVE-2014-4838LOWCVSS 3.5v3.2v3.2.1+8 more2014-10-19
CVE-2014-4838 [LOW] CWE-79 CVE-2014-4838: Cross-site scripting (XSS) vulnerability in GanttProjectSchedulerPopup.jsp in IBM TRIRIGA Applicatio
Cross-site scripting (XSS) vulnerability in GanttProjectSchedulerPopup.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2013-6726LOWCVSS 3.5v3.2v3.2.1+4 more2014-05-07
CVE-2013-6726 [LOW] CWE-79 CVE-2013-6726: Multiple cross-site scripting (XSS) vulnerabilities in WebProcess.srv in IBM TRIRIGA Application Pla
Multiple cross-site scripting (XSS) vulnerabilities in WebProcess.srv in IBM TRIRIGA Application Platform 3.2.x and 3.3.x before 3.3.1.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-4003LOWCVSS 3.5≤ 3.3.0.1v2.1+8 more2013-08-29
CVE-2013-4003 [LOW] CWE-79 CVE-2013-4003: Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x
Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3.1.1, and 8, allow remote authenticated users to inject arbitrary web script or HTML via (1) unspecified input to WebProcess.srv, (2) unspecified input to html/en/default/actionHandler/queryHandler.jsp, or (3) unspecified input in a portalSectionId
nvd
CVE-2012-5950MEDIUMCVSS 6.8v2.1v2.5+7 more2013-04-23
CVE-2012-5950 [MEDIUM] CWE-352 CVE-2012-5950: Multiple cross-site request forgery (CSRF) vulnerabilities in IBM TRIRIGA Application Platform 2.x a
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to hijack the authentication of arbitrary users for requests that modify data records via vectors involving (1) the html/en/default/ directory or (2) sqa/html/en/default/process/comm/saveProps.jsp.
nvd
CVE-2012-5948MEDIUMCVSS 4.3v2.1v2.5+7 more2013-04-23
CVE-2012-5948 [MEDIUM] CWE-79 CVE-2012-5948: Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x
Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) WebProcess.srv, (2) the html/en/default/ directory, (3) Widget/resource, (4) birt/frameset, or (5) ganttlib/gantt-jws.jnlp.
nvd
CVE-2012-5949MEDIUMCVSS 4.3v2.1v2.5+7 more2013-04-23
CVE-2012-5949 [MEDIUM] CWE-79 CVE-2012-5949: Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x
Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject content, and conduct phishing attacks, via vectors involving (1) the html/en/default/ directory, (2) birt/frameset, (3) WebProcess.srv, (4) sqa/html/en/default/reportTemplate/reportTemplateOrderCols.jsp,
nvd
← Previous3 / 3