Vulnerabilities > IBM > Rational Focal Point > 6.4.1.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2014-02-26 | CVE-2014-0853 | Cross-Site Scripting vulnerability in IBM Rational Focal Point Multiple cross-site scripting (XSS) vulnerabilities in the (1) ForwardController and (2) AttributeEditor scripts in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | 3.5 |
2014-02-26 | CVE-2014-0843 | Cross-Site Scripting vulnerability in IBM Rational Focal Point Cross-site scripting (XSS) vulnerability in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allows remote authenticated users to inject arbitrary web script or HTML by uploading a file. | 3.5 |
2014-02-26 | CVE-2014-0842 | Credentials Management vulnerability in IBM Rational Focal Point The account-creation functionality in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 places the new user's default password within the creation page, which allows remote attackers to obtain sensitive information by reading the HTML source code. | 5.0 |
2014-02-26 | CVE-2014-0840 | Cross-Site Scripting vulnerability in IBM Rational Focal Point Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | 3.5 |
2014-02-26 | CVE-2014-0839 | Permissions, Privileges, and Access Controls vulnerability in IBM Rational Focal Point IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allows remote authenticated users to modify data via vectors involving a direct object reference. | 4.0 |