This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Ibm First view 2011-02-14
Product Rational Team Concert Last view 2022-03-15
Version Type
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:ibm:rational_team_concert:6.0.2:*:*:*:*:*:*:* 100
cpe:2.3:a:ibm:rational_team_concert:4.0.4:*:*:*:*:*:*:* 94
cpe:2.3:a:ibm:rational_team_concert:4.0.3:*:*:*:*:*:*:* 94
cpe:2.3:a:ibm:rational_team_concert:4.0.1:*:*:*:*:*:*:* 94
cpe:2.3:a:ibm:rational_team_concert:4.0.2:*:*:*:*:*:*:* 94
cpe:2.3:a:ibm:rational_team_concert:4.0.5:*:*:*:*:*:*:* 94
cpe:2.3:a:ibm:rational_team_concert:4.0.6:*:*:*:*:*:*:* 93
cpe:2.3:a:ibm:rational_team_concert:5.0.1:*:*:*:*:*:*:* 92
cpe:2.3:a:ibm:rational_team_concert:4.0.7:*:*:*:*:*:*:* 91
cpe:2.3:a:ibm:rational_team_concert:5.0.2:*:*:*:*:*:*:* 89
cpe:2.3:a:ibm:rational_team_concert:4.0:*:*:*:*:*:*:* 83
cpe:2.3:a:ibm:rational_team_concert:6.0.1:*:*:*:*:*:*:* 81
cpe:2.3:a:ibm:rational_team_concert:4.0.0.2:*:*:*:*:*:*:* 78
cpe:2.3:a:ibm:rational_team_concert:4.0.0.1:*:*:*:*:*:*:* 78
cpe:2.3:a:ibm:rational_team_concert:5.0.0:*:*:*:*:*:*:* 74
cpe:2.3:a:ibm:rational_team_concert:3.0.1.6:*:*:*:*:*:*:* 73
cpe:2.3:a:ibm:rational_team_concert:5.0:*:*:*:*:*:*:* 72
cpe:2.3:a:ibm:rational_team_concert:4.0.0:*:*:*:*:*:*:* 70
cpe:2.3:a:ibm:rational_team_concert:3.0:*:*:*:*:*:*:* 67
cpe:2.3:a:ibm:rational_team_concert:3.0.1.3:*:*:*:*:*:*:* 65
cpe:2.3:a:ibm:rational_team_concert:6.0:*:*:*:*:*:*:* 65
cpe:2.3:a:ibm:rational_team_concert:3.0.1.4:*:*:*:*:*:*:* 65
cpe:2.3:a:ibm:rational_team_concert:3.0.1.2:*:*:*:*:*:*:* 65
cpe:2.3:a:ibm:rational_team_concert:3.0.1:*:*:*:*:*:*:* 65
cpe:2.3:a:ibm:rational_team_concert:6.0.0:*:*:*:*:*:*:* 65
cpe:2.3:a:ibm:rational_team_concert:3.0.1.5:*:*:*:*:*:*:* 65
cpe:2.3:a:ibm:rational_team_concert:3.0.1.1:*:*:*:*:*:*:* 64
cpe:2.3:a:ibm:rational_team_concert:2.0.0.2:*:*:*:*:*:*:* 64
cpe:2.3:a:ibm:rational_team_concert:6.0.6:*:*:*:*:*:*:* 64
cpe:2.3:a:ibm:rational_team_concert:6.0.3:*:*:*:*:*:*:* 63
cpe:2.3:a:ibm:rational_team_concert:2.0.0.1:*:*:*:*:*:*:* 62
cpe:2.3:a:ibm:rational_team_concert:2.0:*:*:*:*:*:*:* 59
cpe:2.3:a:ibm:rational_team_concert:6.0.6.1:*:*:*:*:*:*:* 52
cpe:2.3:a:ibm:rational_team_concert:6.0.4:*:*:*:*:*:*:* 51
cpe:2.3:a:ibm:rational_team_concert:6.0.6.2:*:*:*:*:*:*:* 8
cpe:2.3:a:ibm:rational_team_concert:7.0:*:*:*:*:*:*:* 4
cpe:2.3:a:ibm:rational_team_concert:7.0.1:*:*:*:*:*:*:* 2
cpe:2.3:a:ibm:rational_team_concert:7.0.2:*:*:*:*:*:*:* 2

Related : CVE

This CPE Product have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
4.3 2022-03-15 CVE-2020-4989

IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 and IBM Rational Team Concert 6.0.6 and 6.0.0.1 could allow an authenticated user to obtain sensitive information about build definitions. IBM X-Force ID: 192707.

4.3 2022-01-11 CVE-2021-29701

IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 as well as IBM Rational Team Concert 6.0.6 and 6.0.6.1 could allow an authneticated attacker to obtain sensitive information from build definitions that could aid in further attacks against the system. IBM X-Force ID: 200657.

8.8 2021-10-27 CVE-2021-29844

IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

6.5 2021-10-27 CVE-2021-29786

IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.

7.5 2021-10-27 CVE-2021-29774

IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.

5.4 2021-10-27 CVE-2021-29713

IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

5.4 2021-10-27 CVE-2021-29673

IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199482.

5.4 2021-07-28 CVE-2020-5004

IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192957.

6.3 2021-07-28 CVE-2020-4974

IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 192434.

5.4 2021-07-19 CVE-2021-20507

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198235.

5.4 2021-07-19 CVE-2020-5031

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193738.

5.4 2021-04-12 CVE-2021-20519

IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198441.

7.5 2021-04-12 CVE-2020-4965

IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192422.

4.3 2021-04-12 CVE-2020-4964

IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users. IBM X-Force ID: 192419.

5.4 2021-04-12 CVE-2020-4920

IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191396.

5.4 2021-03-30 CVE-2021-20520

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198572.

5.4 2021-03-30 CVE-2021-20518

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198437.

5.4 2021-03-30 CVE-2021-20506

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198231.

5.4 2021-03-30 CVE-2021-20504

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198231.

5.4 2021-03-30 CVE-2021-20503

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198182.

7.1 2021-03-30 CVE-2021-20502

IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 198059.

5.4 2021-03-30 CVE-2021-20447

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196623.

5.4 2021-03-30 CVE-2021-20352

IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194710.

5.4 2021-03-04 CVE-2021-20351

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194708.

5.4 2021-03-04 CVE-2021-20350

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194707.

CWE : Common Weakness Enumeration

%idName
62% (83) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
20% (27) CWE-200 Information Exposure
3% (5) CWE-611 Information Leak Through XML External Entity File Disclosure
2% (3) CWE-264 Permissions, Privileges, and Access Controls
1% (2) CWE-326 Inadequate Encryption Strength
1% (2) CWE-209 Information Exposure Through an Error Message
0% (1) CWE-668 Exposure of Resource to Wrong Sphere
0% (1) CWE-552 Files or Directories Accessible to External Parties
0% (1) CWE-384 Session Fixation
0% (1) CWE-352 Cross-Site Request Forgery (CSRF)
0% (1) CWE-327 Use of a Broken or Risky Cryptographic Algorithm
0% (1) CWE-312 Cleartext Storage of Sensitive Information
0% (1) CWE-254 Security Features
0% (1) CWE-94 Failure to Control Generation of Code ('Code Injection')
0% (1) CWE-78 Improper Sanitization of Special Elements used in an OS Command ('O...
0% (1) CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path ...
0% (1) CWE-20 Improper Input Validation

Open Source Vulnerability Database (OSVDB)

id Description
73198 IBM Rational Team Concert Multiple Unspecified XSS
71227 IBM Rational Team Concert Report Name XSS

Nessus® Vulnerability Scanner

id Description
2014-10-06 Name: The remote web application is utilizing an insecure session cookie.
File: ibm_jazz_team_server_cve_2014_3092.nasl - Type: ACT_GATHER_INFO