PT-2018-13396 · Ibm · Ibm Rational Doors Next Generation+6

Published

2018-11-06

·

Updated

2019-10-09

·

CVE-2018-1606

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Rational Collaborative Lifecycle Management versions 5.0 through 5.02 and 6.0 through 6.0.6 IBM Rational DOORS Next Generation versions 5.0 through 5.02 and 6.0 through 6.0.6 IBM Rational Engineering Lifecycle Manager versions 5.0 through 5.02 and 6.0 through 6.0.6 IBM Rational Quality Manager versions 5.0 through 5.02 and 6.0 through 6.0.6 IBM Rational Rhapsody Design Manager versions 5.0 through 5.02 and 6.0 through 6.0.6 IBM Rational Software Architect Design Manager versions 5.0 through 5.02 and 6.0 through 6.0.1 IBM Rational Team Concert versions 5.0 through 5.02 and 6.0 through 6.0.6
Description The issue could allow an authenticated user to obtain sensitive information from an error message that could be used in further attacks against the system.
Recommendations For IBM Rational Collaborative Lifecycle Management versions 5.0 through 5.02 and 6.0 through 6.0.6, update to a version outside of the affected range. For IBM Rational DOORS Next Generation versions 5.0 through 5.02 and 6.0 through 6.0.6, update to a version outside of the affected range. For IBM Rational Engineering Lifecycle Manager versions 5.0 through 5.02 and 6.0 through 6.0.6, update to a version outside of the affected range. For IBM Rational Quality Manager versions 5.0 through 5.02 and 6.0 through 6.0.6, update to a version outside of the affected range. For IBM Rational Rhapsody Design Manager versions 5.0 through 5.02 and 6.0 through 6.0.6, update to a version outside of the affected range. For IBM Rational Software Architect Design Manager versions 5.0 through 5.02 and 6.0 through 6.0.1, update to a version outside of the affected range. For IBM Rational Team Concert versions 5.0 through 5.02 and 6.0 through 6.0.6, update to a version outside of the affected range.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1606

Affected Products

Ibm Rational Collaborative Lifecycle Management
Ibm Rational Doors Next Generation
Ibm Rational Engineering Lifecycle Manager
Ibm Rational Quality Manager
Rational Rhapsody Design Manager
Ibm Rational Software Architect Design Manager
Ibm Rational Team Concert