Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.97% | — | IBM Rational Requirements ComposerIBM Rational Doors Next Generation | 19/7/2018 | 17/6/2026 | IBM Rational DOORS Next Generation 5.0 through 5.0.2, 6.0 through 6.0.5 and IBM Rational Requirements Composer 5.0 through 5.0.2 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to… | |
| Modificada | Media (5.4) | 0.54% | — | IBM Rational Requirements ComposerIBM Rational Doors Next Generation | 12/4/2018 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 5.0, 5.0.1, 5.0.2, and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Baja (3.3) | 0.13% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Requirements Composer+4 | 20/3/2018 | 17/6/2026 | IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Manager (RQM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Team Concert… | |
| Modificada | Media (4.8) | 0.63% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Requirements Composer+4 | 15/3/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7… | |
| Modificada | Media (6.1) | 0.85% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Requirements Composer+4 | 15/3/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7… | |
| Modificada | Alta (7.8) | 0.31% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Requirements Composer+4 | 15/3/2018 | 17/6/2026 | IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x… | |
| Modificada | Media (6.5) | 1.2% | — | IBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Doors Next GenerationIBM Rational Team Concert+4 | 16/1/2018 | 17/6/2026 | XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote authenticated users to cause a denial of service via crafted XML data. IBM X-Force ID: 109693. | |
| Modificada | Media (5.4) | 0.70% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 13/12/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 4.07, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130915. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 18/8/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126246. | |
| Modificada | Media (5.4) | 0.87% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 12/6/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124756. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 12/6/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124751. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 12/6/2017 | 17/6/2026 | IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124627. | |
| Modificada | Media (5.4) | 0.51% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 23/2/2017 | 17/6/2026 | IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1995515. | |
| Modificada | Media (4.3) | 0.68% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 15/2/2017 | 17/6/2026 | An undisclosed vulnerability in IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 could allow a JazzGuest user to see project names. IBM Reference #: 1995547. | |
| Modificada | Media (5.4) | 0.65% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 8/2/2017 | 17/6/2026 | IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (5.4) | 0.65% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 8/2/2017 | 17/6/2026 | IBM Rational DOORS Next Generation 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (4.3) | 0.94% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 8/2/2017 | 17/6/2026 | IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system. | |
| Modificada | Baja (3.5) | 0.45% | — | IBM Rational Rhapsody Design ManagerIBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Engineering Lifecycle Manager+4 | 3/1/2016 | 17/6/2026 | Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Team Concert (RTC) 3.x… | |
| Modificada | Baja (3.3) | 0.30% | — | IBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Engineering Lifecycle ManagerIBM Rational Collaborative Lifecycle Management+4 | 3/1/2016 | 17/6/2026 | Rational LifeCycle Project Administration in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1;… | |
| Modificada | Media (4.3) | 0.55% | — | IBM Rational Quality ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Team ConcertIBM Rational Software Architect Design Manager+4 | 3/1/2016 | 17/6/2026 | Unspecified vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF8, and 5.x before 5.0.2 IF10; Rational Team Concert (RTC)… | |
| Modificada | Media (6.8) | 1.2% | — | IBM Rational Quality ManagerIBM Rational Rhapsody Design ManagerIBM Rational Requirements ComposerIBM Rational Engineering Lifecycle Manager+4 | 2/1/2016 | 17/6/2026 | Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.x before 6.0.0 IF4; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.0 before 6.0.0 IF4; Rational Team Concert… | |
| Modificada | Baja (3.5) | 0.78% | — | IBM Rational Doors Next GenerationIBM Rational Team ConcertIBM Rational Collaborative Lifecycle ManagementIBM Rational Requirements Composer+1 | 20/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Quality Manager (RQM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Team Concert (RTC) 4.x before 4.0.7 IF6 and 5.x… | |
| Modificada | Media (4) | 1.0% | — | IBM Rational Requirements ComposerIBM Rhapsody Design ManagerIBM Rational Team ConcertIBM Rational Quality Manager+4 | 7/6/2015 | 17/6/2026 | Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1, 4.x before 4.0.7 IF5, and 5.x before 5.0.2 IF4; Rational Quality Manager (RQM) 2.0 through 2.0.1, 3.0 through 3.0.1.6, 4.0 through 4.0.7, and 5.0 through 5.0.2; Rational Team Concert (RTC) 2.0 through 2.0.0.2, 3.x… | |
| Modificada | Baja (3.7) | 0.44% | — | IBM Rational Requirements ComposerIBM Rational Doors Next Generation | 30/5/2015 | 17/6/2026 | IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next Generation (RDNG) 4.0 through 4.0.7 and 5.0 through 5.0.2, when LTPA single sign on is used with WebSphere Application Server, do not terminate a Requirements Management (RM) session upon LTPA token expiration, which… | |
| Modificada | Media (5) | 1.2% | — | IBM Rational Software Architect Design ManagerIBM Rational Team ConcertIBM Rational Rhapsody Design ManagerIBM Rational Collaborative Lifecycle Management+4 | 27/4/2015 | 17/6/2026 | The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Requirements Composer 4.0 through 4.0.7, Rational DOORS Next Generation 4.0 through 4.0.7… |