Summary
Detail | |||
---|---|---|---|
Vendor | Ibm | First view | 2008-05-09 |
Product | Rational Build Forge | Last view | 2011-09-08 |
Version | Type | ||
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
CPE Name | Affected CVE |
---|---|
cpe:2.3:a:ibm:rational_build_forge:7.0.2:*:*:*:*:*:*:* | 2 |
cpe:2.3:a:ibm:rational_build_forge:7.1.0:*:*:*:*:*:*:* | 1 |
cpe:2.3:a:ibm:rational_build_forge:7.1.2:*:*:*:*:*:*:* | 1 |
Related : CVE
Date | Alert | Description | |
---|---|---|---|
4 | 2011-09-08 | CVE-2011-3391 | IBM Rational Build Forge 7.1.2 relies on client-side JavaScript code to enforce the EditSecurity permission requirement for the Export Key File function, which allows remote authenticated users to read a key file by removing a disable attribute in the Security sub-menu. |
5 | 2011-04-28 | CVE-2011-1839 | IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history. |
4.3 | 2011-02-15 | CVE-2011-1034 | Cross-site scripting (XSS) vulnerability in the UI in IBM Rational Build Forge 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter to the fullcontrol program. NOTE: some of these details are obtained from third party information. |
7.5 | 2008-05-09 | CVE-2008-2122 | IBM Rational Build Forge 7.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a port scan, which spawns multiple bfagent server processes that attempt to read data from closed sockets. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
25% (1) | CWE-772 | Missing Release of Resource after Effective Lifetime |
25% (1) | CWE-264 | Permissions, Privileges, and Access Controls |
25% (1) | CWE-200 | Information Exposure |
25% (1) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
CAPEC : Common Attack Pattern Enumeration & Classification
id | Name |
---|---|
CAPEC-2 | Inducing Account Lockout |
CAPEC-82 | Violating Implicit Assumptions Regarding XML Content (aka XML Denial of Servi... |
CAPEC-147 | XML Ping of Death |
CAPEC-228 | Resource Depletion through DTD Injection in a SOAP Message |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
74831 | IBM Rational Build Forge EditSecurity Permissions Weakness Information Disclo... |
74179 | IBM Rational Build Forge Authentication Servlet Redirection GET Method Sessio... |
70763 | IBM Rational Build Forge fullcontrol/ Multiple Parameter XSS |
44829 | IBM Rational Build Forge Agent Multiple bfagent Processes CPU Consumption Rem... |