Ibm

Rational Build Forge

4 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Published 08.09.2011 18:55:05
  • Last modified 11.04.2025 00:51:21

IBM Rational Build Forge 7.1.2 relies on client-side JavaScript code to enforce the EditSecurity permission requirement for the Export Key File function, which allows remote authenticated users to read a key file by removing a disable attribute in th...

  • EPSS 0.25%
  • Published 28.04.2011 18:55:01
  • Last modified 11.04.2025 00:51:21

IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-s...

  • EPSS 0.46%
  • Published 16.02.2011 03:00:03
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in the UI in IBM Rational Build Forge 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter to the fullcontrol program. NOTE: some of these details are obtained from third...

  • EPSS 4.73%
  • Published 09.05.2008 15:20:00
  • Last modified 09.04.2025 00:30:58

IBM Rational Build Forge 7.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a port scan, which spawns multiple bfagent server processes that attempt to read data from closed sockets.