Rational Focal Point
Vendor:
First CVE: Oct 17, 2013 · Active for 12 years
9
Total CVEs
More Total CVEs than 88% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
4.0
Avg CVSS
Higher Avg CVSS than 2% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Rational Focal Point over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 17, 2013
12 years ago
Most Recent CVE
Apr 27, 2018
3,014 days ago
CVE Severity & Scoring
Rational Focal Point9 CVEs
56%
44%
All CVEs353,240 CVEs
45%
40%
11%
LowMedium
Attack Vector
Local1 (11.1%)
Network0 (0.0%)
Unknown8 (88.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (11.1%)
High0 (0.0%)
Unknown8 (88.9%)
User Interaction
None1 (11.1%)
Unknown8 (88.9%)
Required0 (0.0%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (88.9%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0839MEDIUM IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allows remote authenticated users to modify data via vectors involving a direct object reference. | Feb 26, 2014 | 4.0 | 17 | NO | NO |
CVE-2013-3025MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.5.x and 6.6.x before 6.6.0.1 allow remote attackers to inject arbitrary web script or HTML via uns | Oct 17, 2013 | 4.3 | 17 | NO | NO |
CVE-2014-0841MEDIUM IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext val | Apr 27, 2018 | 5.3 | 16 | NO | NO |
CVE-2014-0842MEDIUM The account-creation functionality in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 places the new user's default password within the creation page | Feb 26, 2014 | 5.0 | 15 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in the (1) ForwardController and (2) AttributeEditor scripts in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6. | Feb 26, 2014 | 3.5 | 13 | NO | NO |
Cross-site scripting (XSS) vulnerability in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allows remote authenticated users to inject arbitrary web | Feb 26, 2014 | 3.5 | 13 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.4.x and 6.5.x before 6.5.2.3 and 6.6.x before 6.6.1 allow remote authenticated users to inject arb | Feb 26, 2014 | 3.5 | 13 | NO | NO |
Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 | Dec 18, 2013 | 3.3 | 12 | NO | NO |
Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 | Dec 18, 2013 | 3.3 | 12 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Rational Focal Point
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.6.1 | 2 | 3.3 | 0.6% | 0 | 0 |
| 6.6.0.1 | 7 | 3.7 | 0.9% | 0 | 0 |
| 6.6 | 9 | 4.0 | 0.8% | 0 | 0 |
| 6.5.2.3 | 8 | 3.8 | 0.9% | 0 | 0 |
| 6.5.2.2 | 6 | 4.0 | 1.0% | 0 | 0 |
| 6.5.2.1 | 6 | 4.0 | 1.0% | 0 | 0 |
| 6.5.2 | 9 | 4.0 | 0.8% | 0 | 0 |
| 6.5.1.1 | 5 | 3.9 | 1.0% | 0 | 0 |
| 6.5.1 | 8 | 3.9 | 0.8% | 0 | 0 |
| 6.5.0.2 | 5 | 3.9 | 1.0% | 0 | 0 |
| 6.5.0.1 | 5 | 3.9 | 1.0% | 0 | 0 |
| 6.5 | 5 | 3.9 | 1.0% | 0 | 0 |
| 6.4.1.3 | 7 | 3.7 | 0.9% | 0 | 0 |
| 6.4.1.2 | 5 | 3.9 | 1.0% | 0 | 0 |
| 6.4.1.1 | 5 | 3.9 | 1.0% | 0 | 0 |
| 6.4.1.0 | 5 | 3.9 | 1.0% | 0 | 0 |
| 6.4.1 | 1 | 5.3 | 0.2% | 0 | 0 |
| 6.4.0.1 | 5 | 3.9 | 1.0% | 0 | 0 |
| 6.4 | 8 | 3.9 | 0.8% | 0 | 0 |