Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Engineering Lifecycle Manager | 3/10/2017 | 17/6/2026 | IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126686. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Engineering Lifecycle Manager | 3/10/2017 | 17/6/2026 | IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126243. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Engineering Lifecycle Manager | 3/10/2017 | 17/6/2026 | IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126242. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Engineering Lifecycle Manager | 3/10/2017 | 17/6/2026 | IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125975. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Engineering Lifecycle Manager | 10/8/2017 | 17/6/2026 | IBM Rational Engineering Lifecycle Manager 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123187. | |
| Modificada | Media (4.3) | 0.69% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next Generation+3 | 5/7/2017 | 17/6/2026 | IBM Jazz Foundation could allow an authenticated attacker to obtain sensitive information from error message stack traces. IBM X-Force ID: 119528. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Rational Engineering Lifecycle ManagerIBM Rational Collaborative Lifecycle Management | 22/6/2017 | 17/6/2026 | IBM RELM 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (4.3) | 3.4% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next Generation+3 | 13/6/2017 | 17/6/2026 | IBM Jazz Foundation could expose potentially sensitive information to authenticated users through stack trace error conditions. IBM X-Force ID: 120659. | |
| Modificada | Media (5.4) | 0.74% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next Generation+3 | 13/6/2017 | 17/6/2026 | IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120209. | |
| Modificada | Media (4.3) | 0.68% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next Generation+3 | 15/5/2017 | 17/6/2026 | IBM Jazz Foundation could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 119781, | |
| Modificada | Alta (7.5) | 55% | 💥 Exploit | OpensslOracle Agile Engineering Data ManagementOracle Communications Application Session ControllerOracle Communications Eagle LNP Application Processor+3 | 4/5/2017 | 17/6/2026 | In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack. | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa | Apache TomcatCanonical Ubuntu LinuxNetapp 7-mode Transition ToolNetapp Oncommand Insight+15 | 6/4/2017 | 25/8/2026 | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427… | |
| Modificada | Alta (8.1) | 1.5% | — | IBM Rational Rhapsody Design ManagerIBM Rational Quality ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Software Architect Design Manager+3 | 31/3/2017 | 17/6/2026 | IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 2000784. | |
| Modificada | Media (4.3) | 0.77% | — | IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Rhapsody Design Manager+2 | 1/2/2017 | 17/6/2026 | An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker. | |
| Modificada | Media (5.4) | 1.3% | — | IBM Rational Engineering Lifecycle ManagerIBM Rational Rhapsody Design ManagerIBM Rational Quality ManagerIBM Rational Software Architect Design Manager+3 | 30/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Quality Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Team Concert 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational DOORS Next… | |
| Modificada | Media (5.4) | 1.2% | — | IBM Rational Team ConcertIBM Rational Rhapsody Design ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Quality Manager+3 | 25/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Team Concert 4.0 before 4.0.7 iFix11,… | |
| Modificada | Media (5.4) | 0.61% | — | IBM Rational Engineering Lifecycle ManagerIBM Rational Team ConcertIBM Rational Quality ManagerIBM Rational Doors Next Generation+1 | 25/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 6.x before 6.0.1 iFix6, Rational Quality Manager 6.x before 6.0.1 iFix6, Rational Team Concert 6.x before 6.0.1 iFix6, Rational DOORS Next Generation 6.x before 6.0.1 iFix6, Rational Engineering Lifecycle Manager 6.x before… | |
| Modificada | Baja (2.7) | 0.83% | — | IBM Rational Team ConcertIBM Rational Rhapsody Design ManagerIBM Rational Software Architect Design ManagerIBM Rational Doors Next Generation+3 | 25/11/2016 | 17/6/2026 | IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before… | |
| Modificada | Media (5.4) | 0.61% | — | IBM Rational Quality ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Team ConcertIBM Rational Collaborative Lifecycle Management+3 | 24/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5;… | |
| Modificada | Baja (3.7) | 0.88% | — | IBM Rational Team ConcertIBM Rational Quality ManagerIBM Rational Software Architect Design ManagerIBM Rational Collaborative Lifecycle Management+3 | 24/11/2016 | 17/6/2026 | IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8,… | |
| Modificada | Media (5.4) | 0.94% | — | IBM Rational Software Architect Design ManagerIBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Quality Manager+3 | 24/11/2016 | 17/6/2026 | The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert… | |
| Modificada | Media (5.4) | 0.61% | — | IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Collaborative Lifecycle ManagementIBM Rational Quality Manager+3 | 24/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5;… | |
| Modificada | Alta (8.1) | 1.9% | — | Oracle Agile Engineering Data Management | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to webfileservices. | |
| Modificada | Alta (7.5) | 3.6% | — | Indasengineering WEB Scada | 5/10/2016 | 17/6/2026 | Directory traversal vulnerability in INDAS Web SCADA before 3 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (5.4) | 1.3% | — | IBM Engineering Lifecycle Optimization - Publishing | 8/8/2016 | 17/6/2026 | Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to execute arbitrary code by specifying an unexpected file extension. |