This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Ibm First view 2008-05-09
Product Rational Build Forge Last view 2011-09-08
Version Type
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:ibm:rational_build_forge:7.0.2:*:*:*:*:*:*:* 2
cpe:2.3:a:ibm:rational_build_forge:7.1.0:*:*:*:*:*:*:* 1
cpe:2.3:a:ibm:rational_build_forge:7.1.2:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
4 2011-09-08 CVE-2011-3391

IBM Rational Build Forge 7.1.2 relies on client-side JavaScript code to enforce the EditSecurity permission requirement for the Export Key File function, which allows remote authenticated users to read a key file by removing a disable attribute in the Security sub-menu.

5 2011-04-28 CVE-2011-1839

IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

4.3 2011-02-15 CVE-2011-1034

Cross-site scripting (XSS) vulnerability in the UI in IBM Rational Build Forge 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter to the fullcontrol program. NOTE: some of these details are obtained from third party information.

7.5 2008-05-09 CVE-2008-2122

IBM Rational Build Forge 7.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a port scan, which spawns multiple bfagent server processes that attempt to read data from closed sockets.

CWE : Common Weakness Enumeration

%idName
25% (1) CWE-772 Missing Release of Resource after Effective Lifetime
25% (1) CWE-264 Permissions, Privileges, and Access Controls
25% (1) CWE-200 Information Exposure
25% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')

CAPEC : Common Attack Pattern Enumeration & Classification

id Name
CAPEC-2 Inducing Account Lockout
CAPEC-82 Violating Implicit Assumptions Regarding XML Content (aka XML Denial of Servi...
CAPEC-147 XML Ping of Death
CAPEC-228 Resource Depletion through DTD Injection in a SOAP Message

Open Source Vulnerability Database (OSVDB)

id Description
74831 IBM Rational Build Forge EditSecurity Permissions Weakness Information Disclo...
74179 IBM Rational Build Forge Authentication Servlet Redirection GET Method Sessio...
70763 IBM Rational Build Forge fullcontrol/ Multiple Parameter XSS
44829 IBM Rational Build Forge Agent Multiple bfagent Processes CPU Consumption Rem...