CVE-2015-7449
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
20/03/2018
Last modified:
13/04/2018
Description
IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Manager (RQM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Team Concert (RTC) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Requirements Composer (RRC) 4.0.x before 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7 before iFix1, 5.0.x before 5.0.2 iFix1, and 6.0.x before 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Software Architect Design Manager (RSA DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2 allow local users to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 108221.
Impact
Base Score 3.x
3.30
Severity 3.x
LOW
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:*:*:*:*:*:*:*:* | 4.0.0 (including) | 6.0.2 (including) |
| cpe:2.3:a:ibm:rational_quality_manager:*:*:*:*:*:*:*:* | 4.0.0 (including) | 4.0.7 (including) |
| cpe:2.3:a:ibm:rational_quality_manager:5.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:rational_quality_manager:5.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:rational_quality_manager:5.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:rational_quality_manager:6.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:rational_quality_manager:6.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:rational_quality_manager:6.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:rational_team_concert:*:*:*:*:*:*:*:* | 4.0.0 (including) | 4.0.7 (including) |
| cpe:2.3:a:ibm:rational_team_concert:5.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:rational_team_concert:5.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:rational_team_concert:5.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:rational_team_concert:6.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:rational_team_concert:6.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:rational_team_concert:6.0.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



