PT-2016-3588 · Ibm · Ibm Rational Team Concert+7

Published

2016-01-02

·

Updated

2016-12-07

·

CVE-2015-1928

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Rational Collaborative Lifecycle Management (CLM) versions 3.x through 4.0.7 IF8 and 5.x through 5.0.2 IF10 and 6.x through 6.0.0 IF3 Rational Quality Manager (RQM) versions 3.x through 3.0.1.5 IF6 and 4.x through 4.0.7 IF8 and 5.x through 5.0.2 IF10 and 6.0 through 6.0.0 IF3 Rational Team Concert (RTC) versions 3.x through 3.0.1.5 IF6 and 4.x through 4.0.7 IF8 and 5.x through 5.0.2 IF10 and 6.0 through 6.0.0 IF3 Rational Requirements Composer (RRC) versions 3.x through 3.0.1.5 IF6 and 4.x through 4.0.7 IF8 Rational DOORS Next Generation (RDNG) versions 4.x through 4.0.7 IF8 and 5.x through 5.0.2 IF10 and 6.0 through 6.0.0 IF3 Rational Engineering Lifecycle Manager (RELM) versions 4.0.3 through 4.0.7 and 5.0 through 5.0.2 and 6.0.0 Rational Rhapsody Design Manager (DM) versions 4.0 through 4.0.7 and 5.0 through 5.0.2 and 6.0.0 Rational Software Architect Design Manager (DM) versions 4.0 through 4.0.7 and 5.0 through 5.0.2 and 6.0.0
Description The issue allows remote authenticated users to conduct clickjacking attacks via a crafted web site.
Recommendations For IBM Rational Collaborative Lifecycle Management (CLM) versions 3.x through 4.0.7 IF8 and 5.x through 5.0.2 IF10 and 6.x through 6.0.0 IF3, update to version 4.0.7 IF9, 5.0.2 IF11, or 6.0.0 IF4 or later. For Rational Quality Manager (RQM) versions 3.x through 3.0.1.5 IF6 and 4.x through 4.0.7 IF8 and 5.x through 5.0.2 IF10 and 6.0 through 6.0.0 IF3, update to version 3.0.1.6 IF7, 4.0.7 IF9, 5.0.2 IF11, or 6.0.0 IF4 or later. For Rational Team Concert (RTC) versions 3.x through 3.0.1.5 IF6 and 4.x through 4.0.7 IF8 and 5.x through 5.0.2 IF10 and 6.0 through 6.0.0 IF3, update to version 3.0.1.6 IF7, 4.0.7 IF9, 5.0.2 IF11, or 6.0.0 IF4 or later. For Rational Requirements Composer (RRC) versions 3.x through 3.0.1.5 IF6 and 4.x through 4.0.7 IF8, update to version 3.0.1.6 IF7 or 4.0.7 IF9 or later. For Rational DOORS Next Generation (RDNG) versions 4.x through 4.0.7 IF8 and 5.x through 5.0.2 IF10 and 6.0 through 6.0.0 IF3, update to version 4.0.7 IF9, 5.0.2 IF11, or 6.0.0 IF4 or later. For Rational Engineering Lifecycle Manager (RELM) versions 4.0.3 through 4.0.7 and 5.0 through 5.0.2 and 6.0.0, update to a version outside of the specified ranges. For Rational Rhapsody Design Manager (DM) versions 4.0 through 4.0.7 and 5.0 through 5.0.2 and 6.0.0, update to a version outside of the specified ranges. For Rational Software Architect Design Manager (DM) versions 4.0 through 4.0.7 and 5.0 through 5.0.2 and 6.0.0, update to a version outside of the specified ranges.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-1928

Affected Products

Ibm Rational Collaborative Lifecycle Management
Ibm Rational Doors Next Generation
Ibm Rational Engineering Lifecycle Manager
Ibm Rational Quality Manager
Ibm Rational Requirements Composer
Rational Rhapsody Design Manager
Ibm Rational Software Architect Design Manager
Ibm Rational Team Concert