Show filters
61 Total Results
Displaying 11-20 of 61
Sort by:
Attacker Value
Unknown

CVE-2020-4544

Disclosure Date: January 07, 2021 (last updated February 22, 2025)
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 183189.
Attacker Value
Unknown

CVE-2020-4525

Disclosure Date: August 03, 2020 (last updated February 21, 2025)
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182435.
Attacker Value
Unknown

CVE-2020-4410

Disclosure Date: August 03, 2020 (last updated November 28, 2024)
IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to send a specially crafted HTTP GET request to read attachments on the server that they should not have access to. IBM X-Force ID: 179539.
Attacker Value
Unknown

CVE-2019-4748

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173174.
Attacker Value
Unknown

CVE-2017-1237

Disclosure Date: July 06, 2018 (last updated November 27, 2024)
IBM Jazz based applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124355.
0
Attacker Value
Unknown

CVE-2017-1509

Disclosure Date: July 06, 2018 (last updated November 27, 2024)
IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from a stack trace that could be used to aid future attacks. IBM X-Force ID: 129719.
0
Attacker Value
Unknown

CVE-2017-1559

Disclosure Date: July 06, 2018 (last updated November 27, 2024)
Multiple IBM Rational products could disclose sensitive information by an attacker that intercepts vulnerable requests. IBM X-Force ID: 131758.
0
Attacker Value
Unknown

CVE-2017-1488

Disclosure Date: July 06, 2018 (last updated November 27, 2024)
An undisclosed vulnerability in Jazz common products exists with potential for information disclosure. IBM X-Force ID: 128627.
0
Attacker Value
Unknown

CVE-2018-1456

Disclosure Date: June 06, 2018 (last updated November 26, 2024)
IBM Rhapsody DM 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 140091.
0
Attacker Value
Unknown

CVE-2017-1602

Disclosure Date: March 23, 2018 (last updated November 26, 2024)
IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially crafted URL. IBM X-Force ID: 132625.
0