CVE-2025-33077
- EPSS 0.09%
- Published 23.07.2025 14:49:24
- Last modified 07.08.2025 14:40:39
IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
CVE-2025-33076
- EPSS 0.09%
- Published 23.07.2025 14:48:55
- Last modified 07.08.2025 14:41:12
IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
CVE-2025-33020
- EPSS 0.01%
- Published 23.07.2025 14:47:29
- Last modified 11.08.2025 18:56:26
IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 transmits sensitive information without encryption that could allow an attacker to obtain highly sensitive information.
CVE-2021-20357
- EPSS 0.16%
- Published 27.01.2021 17:15:14
- Last modified 21.11.2024 05:46:27
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust...
CVE-2020-4865
- EPSS 0.21%
- Published 27.01.2021 17:15:13
- Last modified 21.11.2024 05:33:20
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust...
CVE-2020-4855
- EPSS 0.16%
- Published 27.01.2021 17:15:12
- Last modified 21.11.2024 05:33:19
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust...
CVE-2020-4547
- EPSS 0.09%
- Published 27.01.2021 17:15:11
- Last modified 21.11.2024 05:32:52
IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and ...
CVE-2020-4524
- EPSS 0.16%
- Published 27.01.2021 17:15:11
- Last modified 21.11.2024 05:32:50
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust...
CVE-2019-4748
- EPSS 0.18%
- Published 16.07.2020 15:15:27
- Last modified 21.11.2024 04:44:05
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi...
CVE-2017-1287
- EPSS 0.1%
- Published 24.07.2017 21:29:00
- Last modified 20.04.2025 01:37:25
IBM Rhapsody DM 5.0 and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL di...