Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
176 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.77% | — | IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Rhapsody Design Manager+2 | 1/2/2017 | 17/6/2026 | An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker. | |
| Modificada | Media (5.4) | 1.3% | — | IBM Rational Engineering Lifecycle ManagerIBM Rational Rhapsody Design ManagerIBM Rational Quality ManagerIBM Rational Software Architect Design Manager+3 | 30/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Quality Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Team Concert 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational DOORS Next… | |
| Modificada | Media (5.4) | 1.2% | — | IBM Rational Team ConcertIBM Rational Rhapsody Design ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Quality Manager+3 | 25/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Team Concert 4.0 before 4.0.7 iFix11,… | |
| Modificada | Media (5.4) | 0.80% | — | IBM Rational Doors Next Generation | 25/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 6.0.2 before iFix004 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 0.61% | — | IBM Rational Engineering Lifecycle ManagerIBM Rational Team ConcertIBM Rational Quality ManagerIBM Rational Doors Next Generation+1 | 25/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 6.x before 6.0.1 iFix6, Rational Quality Manager 6.x before 6.0.1 iFix6, Rational Team Concert 6.x before 6.0.1 iFix6, Rational DOORS Next Generation 6.x before 6.0.1 iFix6, Rational Engineering Lifecycle Manager 6.x before… | |
| Modificada | Baja (2.7) | 0.83% | — | IBM Rational Team ConcertIBM Rational Rhapsody Design ManagerIBM Rational Software Architect Design ManagerIBM Rational Doors Next Generation+3 | 25/11/2016 | 17/6/2026 | IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before… | |
| Modificada | Media (5.4) | 0.61% | — | IBM Rational Quality ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Team ConcertIBM Rational Collaborative Lifecycle Management+3 | 24/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5;… | |
| Modificada | Baja (3.7) | 0.88% | — | IBM Rational Team ConcertIBM Rational Quality ManagerIBM Rational Software Architect Design ManagerIBM Rational Collaborative Lifecycle Management+3 | 24/11/2016 | 17/6/2026 | IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8,… | |
| Modificada | Media (5.4) | 0.94% | — | IBM Rational Software Architect Design ManagerIBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Quality Manager+3 | 24/11/2016 | 17/6/2026 | The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert… | |
| Modificada | Media (5.4) | 0.61% | — | IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Collaborative Lifecycle ManagementIBM Rational Quality Manager+3 | 24/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5;… | |
| Modificada | Baja (3.5) | 0.45% | — | IBM Rational Rhapsody Design ManagerIBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Engineering Lifecycle Manager+4 | 3/1/2016 | 17/6/2026 | Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Team Concert (RTC) 3.x… | |
| Modificada | Baja (3.3) | 0.30% | — | IBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Engineering Lifecycle ManagerIBM Rational Collaborative Lifecycle Management+4 | 3/1/2016 | 17/6/2026 | Rational LifeCycle Project Administration in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1;… | |
| Modificada | Media (4.3) | 0.55% | — | IBM Rational Quality ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Team ConcertIBM Rational Software Architect Design Manager+4 | 3/1/2016 | 17/6/2026 | Unspecified vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF8, and 5.x before 5.0.2 IF10; Rational Team Concert (RTC)… | |
| Modificada | Media (6.8) | 1.2% | — | IBM Rational Quality ManagerIBM Rational Rhapsody Design ManagerIBM Rational Requirements ComposerIBM Rational Engineering Lifecycle Manager+4 | 2/1/2016 | 17/6/2026 | Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.x before 6.0.0 IF4; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.0 before 6.0.0 IF4; Rational Team Concert… | |
| Modificada | Baja (3.5) | 0.78% | — | IBM Rational Doors Next GenerationIBM Rational Team ConcertIBM Rational Collaborative Lifecycle ManagementIBM Rational Requirements Composer+1 | 20/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Quality Manager (RQM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Team Concert (RTC) 4.x before 4.0.7 IF6 and 5.x… | |
| Modificada | Media (4) | 1.0% | — | IBM Rational Requirements ComposerIBM Rhapsody Design ManagerIBM Rational Team ConcertIBM Rational Quality Manager+4 | 7/6/2015 | 17/6/2026 | Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1, 4.x before 4.0.7 IF5, and 5.x before 5.0.2 IF4; Rational Quality Manager (RQM) 2.0 through 2.0.1, 3.0 through 3.0.1.6, 4.0 through 4.0.7, and 5.0 through 5.0.2; Rational Team Concert (RTC) 2.0 through 2.0.0.2, 3.x… | |
| Modificada | Baja (3.7) | 0.44% | — | IBM Rational Requirements ComposerIBM Rational Doors Next Generation | 30/5/2015 | 17/6/2026 | IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next Generation (RDNG) 4.0 through 4.0.7 and 5.0 through 5.0.2, when LTPA single sign on is used with WebSphere Application Server, do not terminate a Requirements Management (RM) session upon LTPA token expiration, which… | |
| Modificada | Media (5) | 1.2% | — | IBM Rational Software Architect Design ManagerIBM Rational Team ConcertIBM Rational Rhapsody Design ManagerIBM Rational Collaborative Lifecycle Management+4 | 27/4/2015 | 17/6/2026 | The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Requirements Composer 4.0 through 4.0.7, Rational DOORS Next Generation 4.0 through 4.0.7… | |
| Modificada | Alta (7.8) | 1.3% | — | IBM Rational Requirements ComposerIBM Rational Doors Next Generation | 18/3/2015 | 17/6/2026 | The XML parser in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5 and 4.x before 4.0.7 iFix3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory… | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Rational Requirements ComposerIBM Rational Doors Next Generation | 18/3/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 4.x before 4.0.7 iFix3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (4) | 1.3% | — | IBM Rational Doors Next GenerationIBM Rational Requirements ComposerIBM Rational Collaborative Lifecycle ManagementIBM Rational Team Concert+1 | 18/3/2015 | 17/6/2026 | IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5,… | |
| Modificada | Media (5.5) | 1.4% | — | IBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Doors Next GenerationIBM Rational Team Concert+1 | 18/3/2015 | 17/6/2026 | IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5,… | |
| Modificada | Media (5) | 1.7% | — | IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Requirements Composer+3 | 12/9/2014 | 17/6/2026 | IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to… | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 4/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (4.9) | 0.95% | — | IBM Rational Requirements ComposerIBM Rational Doors Next Generation | 4/3/2014 | 17/6/2026 | Open redirect vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. |