Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

104 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)2.0%—IBM Rational Rhapsody Design Manager8/6/201717/6/2026
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1999960.
ModificadaMedia (4.3)0.68%—IBM Rational Collaborative Lifecycle ManagementIBM Rational Quality ManagerIBM Rational Team ConcertIBM Rational Doors Next Generation+315/5/201717/6/2026
IBM Jazz Foundation could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 119781,
ModificadaAlta (8.1)1.5%—IBM Rational Rhapsody Design ManagerIBM Rational Quality ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Software Architect Design Manager+331/3/201717/6/2026
IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 2000784.
ModificadaBaja (3.1)0.66%—IBM Rational Rhapsody Design Manager20/3/201717/6/2026
An unspecified vulnerability in IBM Rhapsody DM 4.0, 5.0, and 6.0 could allow an attacker to perform a JSON Hijacking Attack. A JSON Hijacking Attack may expose to an attacker information passed between the server and the browser. IBM Reference #: 1999960.
ModificadaMedia (5.4)0.64%—IBM Rational Rhapsody Design Manager20/3/201717/6/2026
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM Reference #: 1999960.
ModificadaMedia (5.4)0.54%—IBM Rational Rhapsody Design Manager20/3/201717/6/2026
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999960.
ModificadaMedia (4.3)0.67%—IBM Rational Rhapsody Design Manager20/3/201717/6/2026
IBM Rhapsody DM 4.0, 5.0 and 6.0 contains an undisclosed vulnerability that may allow an authenticated user to upload infected malicious files to the server. IBM Reference #: 1999960.
ModificadaAlta (8.1)1.2%—IBM Rational Rhapsody Design Manager23/2/201717/6/2026
IBM Rhapsody DM 4.0, 5.0 and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1997798.
ModificadaMedia (4.3)0.77%—IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Rhapsody Design Manager+21/2/201717/6/2026
An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker.
ModificadaMedia (5.4)1.3%—IBM Rational Engineering Lifecycle ManagerIBM Rational Rhapsody Design ManagerIBM Rational Quality ManagerIBM Rational Software Architect Design Manager+330/11/201617/6/2026
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Quality Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Team Concert 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational DOORS Next…
ModificadaMedia (5.4)1.2%—IBM Rational Team ConcertIBM Rational Rhapsody Design ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Quality Manager+325/11/201617/6/2026
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Team Concert 4.0 before 4.0.7 iFix11,…
ModificadaMedia (5.4)0.61%—IBM Rational Engineering Lifecycle ManagerIBM Rational Team ConcertIBM Rational Quality ManagerIBM Rational Doors Next Generation+125/11/201617/6/2026
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 6.x before 6.0.1 iFix6, Rational Quality Manager 6.x before 6.0.1 iFix6, Rational Team Concert 6.x before 6.0.1 iFix6, Rational DOORS Next Generation 6.x before 6.0.1 iFix6, Rational Engineering Lifecycle Manager 6.x before…
ModificadaBaja (2.7)0.83%—IBM Rational Team ConcertIBM Rational Rhapsody Design ManagerIBM Rational Software Architect Design ManagerIBM Rational Doors Next Generation+325/11/201617/6/2026
IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before…
ModificadaMedia (5.4)0.61%—IBM Rational Quality ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Team ConcertIBM Rational Collaborative Lifecycle Management+324/11/201617/6/2026
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5;…
ModificadaBaja (3.7)0.88%—IBM Rational Team ConcertIBM Rational Quality ManagerIBM Rational Software Architect Design ManagerIBM Rational Collaborative Lifecycle Management+324/11/201617/6/2026
IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8,…
ModificadaMedia (5.4)0.94%—IBM Rational Software Architect Design ManagerIBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Quality Manager+324/11/201617/6/2026
The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert…
ModificadaMedia (5.4)0.61%—IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Collaborative Lifecycle ManagementIBM Rational Quality Manager+324/11/201617/6/2026
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5;…
ModificadaBaja (3.5)0.45%—IBM Rational Rhapsody Design ManagerIBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Engineering Lifecycle Manager+43/1/201617/6/2026
Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Team Concert (RTC) 3.x…
ModificadaBaja (3.3)0.30%—IBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Engineering Lifecycle ManagerIBM Rational Collaborative Lifecycle Management+43/1/201617/6/2026
Rational LifeCycle Project Administration in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1;…
ModificadaMedia (4.3)0.55%—IBM Rational Quality ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Team ConcertIBM Rational Software Architect Design Manager+43/1/201617/6/2026
Unspecified vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF8, and 5.x before 5.0.2 IF10; Rational Team Concert (RTC)…
ModificadaMedia (6.8)1.2%—IBM Rational Quality ManagerIBM Rational Rhapsody Design ManagerIBM Rational Requirements ComposerIBM Rational Engineering Lifecycle Manager+42/1/201617/6/2026
Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.x before 6.0.0 IF4; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.0 before 6.0.0 IF4; Rational Team Concert…
ModificadaMedia (4)1.0%—IBM Rational Requirements ComposerIBM Rhapsody Design ManagerIBM Rational Team ConcertIBM Rational Quality Manager+47/6/201517/6/2026
Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1, 4.x before 4.0.7 IF5, and 5.x before 5.0.2 IF4; Rational Quality Manager (RQM) 2.0 through 2.0.1, 3.0 through 3.0.1.6, 4.0 through 4.0.7, and 5.0 through 5.0.2; Rational Team Concert (RTC) 2.0 through 2.0.0.2, 3.x…
ModificadaMedia (5)1.2%—IBM Rational Software Architect Design ManagerIBM Rational Team ConcertIBM Rational Rhapsody Design ManagerIBM Rational Collaborative Lifecycle Management+427/4/201517/6/2026
The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Requirements Composer 4.0 through 4.0.7, Rational DOORS Next Generation 4.0 through 4.0.7…
ModificadaMedia (5)1.7%—IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Requirements Composer+312/9/201417/6/2026
IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to…
ModificadaMedia (6)0.78%—IBM Rational Rhapsody Design ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Software Architect Design Manager10/9/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in IBM Configuration Management Application (aka VVC) in IBM Rational Engineering Lifecycle Manager before 4.0.7 and 5.x before 5.0.1, Rational Software Architect Design Manager before 4.0.7 and 5.x before 5.0.1, and Rational Rhapsody Design Manager before 4.0.7 and 5.x…
Orbitaley — Vulnerabilidades