Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.3% | — | IBM Rational Requirements ComposerIBM Rational Doors Next Generation | 18/3/2015 | 17/6/2026 | The XML parser in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5 and 4.x before 4.0.7 iFix3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory… | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Rational Requirements ComposerIBM Rational Doors Next Generation | 18/3/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 4.x before 4.0.7 iFix3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (4) | 1.3% | — | IBM Rational Doors Next GenerationIBM Rational Requirements ComposerIBM Rational Collaborative Lifecycle ManagementIBM Rational Team Concert+1 | 18/3/2015 | 17/6/2026 | IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5,… | |
| Modificada | Media (5.5) | 1.4% | — | IBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Doors Next GenerationIBM Rational Team Concert+1 | 18/3/2015 | 17/6/2026 | IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5,… | |
| Modificada | Media (5) | 1.7% | — | IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Requirements Composer+3 | 12/9/2014 | 17/6/2026 | IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to… | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 4/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (4.9) | 0.95% | — | IBM Rational Requirements ComposerIBM Rational Doors Next Generation | 4/3/2014 | 17/6/2026 | Open redirect vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. | |
| Modificada | Baja (3.5) | 0.85% | — | IBM Rational Requirements ComposerIBM Rational Doors Next Generation | 4/3/2014 | 17/6/2026 | Unspecified vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to read arbitrary data via unknown vectors. | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Team Concert | 10/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other products, allows remote authenticated users to inject arbitrary… | |
| Modificada | Media (5.4) | 0.43% | — | IBM Rational Requirements Composer | 12/9/2013 | 16/6/2026 | IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Rational Requirements Composer | 12/9/2013 | 16/6/2026 | Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for remote attackers to discover credentials via unknown vectors. | |
| Modificada | Media (4.4) | 0.29% | — | IBM Rational Requirements Composer | 12/9/2013 | 16/6/2026 | Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for local users to gain privileges via unknown vectors. | |
| Modificada | Media (4.9) | 0.85% | — | IBM Rational Requirements Composer | 12/9/2013 | 16/6/2026 | Open redirect vulnerability in IBM Rational Requirements Composer before 4.0.4 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. |