Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
188 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.51% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 23/2/2017 | 17/6/2026 | IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1995515. | |
| Modificada | Media (4.3) | 0.68% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 15/2/2017 | 17/6/2026 | An undisclosed vulnerability in IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 could allow a JazzGuest user to see project names. IBM Reference #: 1995547. | |
| Modificada | Media (5.4) | 0.65% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 8/2/2017 | 17/6/2026 | IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (5.4) | 0.65% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 8/2/2017 | 17/6/2026 | IBM Rational DOORS Next Generation 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (4.3) | 0.94% | — | IBM Rational Doors Next GenerationIBM Rational Requirements Composer | 8/2/2017 | 17/6/2026 | IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system. | |
| Modificada | Media (4.3) | 0.77% | — | IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Rhapsody Design Manager+2 | 1/2/2017 | 17/6/2026 | An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker. | |
| Modificada | Media (5.4) | 1.3% | — | IBM Rational Engineering Lifecycle ManagerIBM Rational Rhapsody Design ManagerIBM Rational Quality ManagerIBM Rational Software Architect Design Manager+3 | 30/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Quality Manager 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational Team Concert 4.0 before 4.0.7 iFix11 and 5.0 before 5.0.2 iFix17, Rational DOORS Next… | |
| Modificada | Media (5.4) | 1.2% | — | IBM Rational Team ConcertIBM Rational Rhapsody Design ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Quality Manager+3 | 25/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix19, and 6.0 before 6.0.2 iFix3; Rational Team Concert 4.0 before 4.0.7 iFix11,… | |
| Modificada | Media (5.4) | 0.80% | — | IBM Rational Doors Next Generation | 25/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 6.0.2 before iFix004 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 0.61% | — | IBM Rational Engineering Lifecycle ManagerIBM Rational Team ConcertIBM Rational Quality ManagerIBM Rational Doors Next Generation+1 | 25/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 6.x before 6.0.1 iFix6, Rational Quality Manager 6.x before 6.0.1 iFix6, Rational Team Concert 6.x before 6.0.1 iFix6, Rational DOORS Next Generation 6.x before 6.0.1 iFix6, Rational Engineering Lifecycle Manager 6.x before… | |
| Modificada | Baja (2.7) | 0.83% | — | IBM Rational Team ConcertIBM Rational Rhapsody Design ManagerIBM Rational Software Architect Design ManagerIBM Rational Doors Next Generation+3 | 25/11/2016 | 17/6/2026 | IBM Rational Collaborative Lifecycle Management 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before… | |
| Modificada | Media (5.4) | 0.61% | — | IBM Rational Quality ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Team ConcertIBM Rational Collaborative Lifecycle Management+3 | 24/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5;… | |
| Modificada | Baja (3.7) | 0.88% | — | IBM Rational Team ConcertIBM Rational Quality ManagerIBM Rational Software Architect Design ManagerIBM Rational Collaborative Lifecycle Management+3 | 24/11/2016 | 17/6/2026 | IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8,… | |
| Modificada | Media (5.4) | 0.94% | — | IBM Rational Software Architect Design ManagerIBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Quality Manager+3 | 24/11/2016 | 17/6/2026 | The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert… | |
| Modificada | Media (5.4) | 0.61% | — | IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Collaborative Lifecycle ManagementIBM Rational Quality Manager+3 | 24/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5;… | |
| Modificada | Baja (3.5) | 0.45% | — | IBM Rational Rhapsody Design ManagerIBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Engineering Lifecycle Manager+4 | 3/1/2016 | 17/6/2026 | Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Team Concert (RTC) 3.x… | |
| Modificada | Baja (3.3) | 0.30% | — | IBM Rational Quality ManagerIBM Rational Requirements ComposerIBM Rational Engineering Lifecycle ManagerIBM Rational Collaborative Lifecycle Management+4 | 3/1/2016 | 17/6/2026 | Rational LifeCycle Project Administration in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1;… | |
| Modificada | Media (4.3) | 0.55% | — | IBM Rational Quality ManagerIBM Rational Engineering Lifecycle ManagerIBM Rational Team ConcertIBM Rational Software Architect Design Manager+4 | 3/1/2016 | 17/6/2026 | Unspecified vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF8, and 5.x before 5.0.2 IF10; Rational Team Concert (RTC)… | |
| Modificada | Media (6.8) | 1.2% | — | IBM Rational Quality ManagerIBM Rational Rhapsody Design ManagerIBM Rational Requirements ComposerIBM Rational Engineering Lifecycle Manager+4 | 2/1/2016 | 17/6/2026 | Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.x before 6.0.0 IF4; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.0 before 6.0.0 IF4; Rational Team Concert… | |
| Modificada | Baja (3.5) | 0.78% | — | IBM Rational Doors Next GenerationIBM Rational Team ConcertIBM Rational Collaborative Lifecycle ManagementIBM Rational Requirements Composer+1 | 20/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Quality Manager (RQM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Team Concert (RTC) 4.x before 4.0.7 IF6 and 5.x… | |
| Modificada | Media (4) | 1.0% | — | IBM Rational Requirements ComposerIBM Rhapsody Design ManagerIBM Rational Team ConcertIBM Rational Quality Manager+4 | 7/6/2015 | 17/6/2026 | Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1, 4.x before 4.0.7 IF5, and 5.x before 5.0.2 IF4; Rational Quality Manager (RQM) 2.0 through 2.0.1, 3.0 through 3.0.1.6, 4.0 through 4.0.7, and 5.0 through 5.0.2; Rational Team Concert (RTC) 2.0 through 2.0.0.2, 3.x… | |
| Modificada | Baja (3.7) | 0.44% | — | IBM Rational Requirements ComposerIBM Rational Doors Next Generation | 30/5/2015 | 17/6/2026 | IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next Generation (RDNG) 4.0 through 4.0.7 and 5.0 through 5.0.2, when LTPA single sign on is used with WebSphere Application Server, do not terminate a Requirements Management (RM) session upon LTPA token expiration, which… | |
| Modificada | Media (5) | 1.2% | — | IBM Rational Software Architect Design ManagerIBM Rational Team ConcertIBM Rational Rhapsody Design ManagerIBM Rational Collaborative Lifecycle Management+4 | 27/4/2015 | 17/6/2026 | The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Requirements Composer 4.0 through 4.0.7, Rational DOORS Next Generation 4.0 through 4.0.7… | |
| Modificada | Alta (7.8) | 1.3% | — | IBM Rational Requirements ComposerIBM Rational Doors Next Generation | 18/3/2015 | 17/6/2026 | The XML parser in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5 and 4.x before 4.0.7 iFix3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory… | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Rational Requirements ComposerIBM Rational Doors Next Generation | 18/3/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 4.x before 4.0.7 iFix3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. |