← Back

Rational Doors Web Access

rational_doors_web_access

Vendor: Ibm • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Rational Doors Web Access
Nov 21, 2024
May 16, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Rational DOORS Web Access 9.5.1 through 9.5.2.9, and 9.6 through 9.6.1.9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inten...Show more
IBM Rational DOORS Web Access 9.5.1 through 9.5.2.9, and 9.6 through 9.6.1.9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153916.Show less
1Ibm
1Rational Doors Web Access
Apr 29, 2026
Jul 7, 2011
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Login component in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 allows remote authenticated users to cause a denial of service (license consumption) by trying to login to DOORS Web Access with a new user accoun...Show more
The Login component in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 allows remote authenticated users to cause a denial of service (license consumption) by trying to login to DOORS Web Access with a new user account that has never been used for a DOORS login.Show less
1Ibm
1Rational Doors Web Access
Apr 29, 2026
Jul 7, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 does not properly handle exceptions, which has unspecified impact and remote attack vectors.
1Ibm
1Rational Doors Web Access
Apr 29, 2026
Jul 7, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 has unknown impact and remote attack vectors related to the "server error response."
1Ibm
1Rational Doors Web Access
Apr 29, 2026
Jul 7, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.