|
197241
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_doors_next_generation doors_next engineering_workflow_management engineering_test_management engineering_lifecycle_management…
|
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially …
|
CWE-79
Cross-site Scripting
|
CVE-2020-4866
|
2024-11-21 14:33 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197242
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_doors_next_generation doors_next engineering_workflow_management engineering_test_management engineering_lifecycle_management…
|
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality poten…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4863
|
2024-11-21 14:33 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197243
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_doors_next_generation doors_next engineering_workflow_management engineering_test_management engineering_lifecycle_management…
|
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality poten…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4857
|
2024-11-21 14:33 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197244
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_doors_next_generation doors_next engineering_workflow_management engineering_test_management engineering_lifecycle_management…
|
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality poten…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4856
|
2024-11-21 14:33 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197245
|
3.3 |
LOW
Local
|
ibm
|
cloud_application_performance_management
|
The IBM Application Performance Monitoring UI (IBM Cloud APM 8.1.4) allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 187975.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-4726
|
2024-11-21 14:33 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197246
|
3.5 |
LOW
Network
|
ibm
|
cloud_application_performance_management
|
IBM Monitoring (IBM Cloud APM 8.1.4 ) could allow an authenticated user to modify HTML content by sending a specially crafted HTTP request to the APM UI, which could mislead another user. IBM X-Force…
|
NVD-CWE-Other
|
CVE-2020-4725
|
2024-11-21 14:33 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197247
|
4.9 |
MEDIUM
Network
|
ibm
|
cloud_application_performance_management
|
The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management Webhook URL configuration definition. This could enable an authenticated user w…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2020-4719
|
2024-11-21 14:33 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197248
|
6.5 |
MEDIUM
Network
|
ibm
|
mq
|
IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to an issue processing messages. IBM X-Force ID: 191747.
|
NVD-CWE-noinfo
|
CVE-2020-4931
|
2024-11-21 14:33 |
2021-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197249
|
4.3 |
MEDIUM
Network
|
ibm
|
planning_analytics
|
IBM Planning Analytics 2.0 could allow a remote authenticated attacker to obtain information about an organization's internal structure by exposing sensitive information in HTTP repsonses. IBM X-Forc…
|
CWE-200
Information Exposure
|
CVE-2020-4953
|
2024-11-21 14:33 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197250
|
5.4 |
MEDIUM
Network
|
ibm
|
jazz_reporting_service
|
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the int…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4933
|
2024-11-21 14:33 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|