Vulnerabilities > IBM > Rational Focal Point > 6.4

DATE CVE VULNERABILITY TITLE RISK
2018-04-27 CVE-2014-0841 Inadequate Encryption Strength vulnerability in IBM Rational Focal Point
IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack.
local
low complexity
ibm CWE-326
2.1
2014-02-26 CVE-2014-0853 Cross-Site Scripting vulnerability in IBM Rational Focal Point
Multiple cross-site scripting (XSS) vulnerabilities in the (1) ForwardController and (2) AttributeEditor scripts in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
3.5
2014-02-26 CVE-2014-0843 Cross-Site Scripting vulnerability in IBM Rational Focal Point
Cross-site scripting (XSS) vulnerability in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allows remote authenticated users to inject arbitrary web script or HTML by uploading a file.
network
ibm CWE-79
3.5
2014-02-26 CVE-2014-0842 Credentials Management vulnerability in IBM Rational Focal Point
The account-creation functionality in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 places the new user's default password within the creation page, which allows remote attackers to obtain sensitive information by reading the HTML source code.
network
low complexity
ibm CWE-255
5.0
2014-02-26 CVE-2014-0840 Cross-Site Scripting vulnerability in IBM Rational Focal Point
Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
3.5
2014-02-26 CVE-2014-0839 Permissions, Privileges, and Access Controls vulnerability in IBM Rational Focal Point
IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allows remote authenticated users to modify data via vectors involving a direct object reference.
network
low complexity
ibm CWE-264
4.0
2013-12-18 CVE-2013-5398 Information Disclosure vulnerability in IBM Rational Focal Point Webservice Axis Gateway
Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-5397.
low complexity
ibm
3.3
2013-12-18 CVE-2013-5397 Information Disclosure vulnerability in IBM Rational Focal Point Webservice Axis Gateway
Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-5398.
low complexity
ibm
3.3