Skip to main content

Vendor/product archive

ibm / tririga_application_platform CVEs

Beta · best-effort

47 CVEs tagged to ibm / tririga_application_platform0 Critical, 13 High, 27 Medium, 7 Low, 0 Unrated.

CVE-2026-11372

Published Jun 22, 2026

IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in t…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-4868

Published Jul 31, 2023

IBM TRIRIGA 3.0, 4.0, and 4.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27876

Published Apr 7, 2023

IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive inf…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43914

Published Apr 7, 2023

IBM TRIRIGA Application Platform 4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inte…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4277

Published Apr 17, 2020

IBM TRIRIGA Application Platform 3.5.3 and 3.6.1 discloses sensitive information in error messages that could aid an attacker formulate future attacks. IBM X-Force ID: 175993.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4208

Published May 7, 2019

IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vuln…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4207

Published May 7, 2019

IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 may disclose sensitive information only available to a local user that could be used in further attacks against the system. IBM X-…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-2008

Published May 7, 2019

IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 could disclose sensitive information to an authenticated user that could aid in further attacks against the system. IBM X-Force ID…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0299

Published Feb 28, 2018

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to obtain sensitive information via vectors involving a dat…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0348

Published Feb 21, 2018

Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3, 3.3.1, 3.3.2, and 3.4 allows remote attackers to hijack the authentication of arbitrary us…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0345

Published Feb 21, 2018

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain the installation path via vectors invol…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0344

Published Feb 21, 2018

Cross-site scripting (XSS) vulnerability in the My Reports component in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remo…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0343

Published Feb 21, 2018

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain sensitive information by reading an err…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0342

Published Feb 2, 2018

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to read or modify arbitrary reports by leveraging…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0312

Published Feb 2, 2018

IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors related to granting unauthenticated access to Document Manager. I…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0300

Published Feb 2, 2018

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 might allow remote attackers to access arbitrary JSP pages via vectors related to i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1465

Published Dec 7, 2017

IBM TRIRIGA 3.2, 3.3, 3.4, and 3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attack…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1374

Published Jul 21, 2017

Sensitive data can be exposed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 that can lead to an attacker gaining unauthorized access to the system. IBM X-Force ID: 126…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1373

Published Jul 21, 2017

Reports executed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute a report they do not have acc…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1372

Published Jul 21, 2017

IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1371

Published Jul 21, 2017

Builder tools running in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute Builder tool actions the…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1180

Published Apr 5, 2017

The IBM TRIRIGA Document Manager contains a vulnerability that could allow an authenticated user to execute actions they did not have access to. IBM Reference #: 2001084.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1171

Published Mar 31, 2017

The IBM TRIRIGA Application Platform 3.3, 3,4, and 3,5 contain a vulnerability that could allow an authenticated user to execute Application actions they do not have access to. IB…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1153

Published Mar 27, 2017

IBM TRIRIGA Report Manager 3.2 through 3.5 contains a vulnerability that could allow an authenticated user to execute actions that they do not have access to. IBM Reference #: 199…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9737

Published Mar 27, 2017

IBM TRIRIGA 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fu…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 47 CVEsPage 1 of 2