PT-2018-4415 · Ibm · Ibm Rational Team Concert+7

Published

2018-03-20

·

Updated

2018-04-13

·

CVE-2015-7449

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Rational Collaborative Lifecycle Management (CLM) versions 4.0.x through 4.0.7 before iFix10, 5.0.x through 5.0.2 before iFix15, 6.0.x through 6.0.1 before iFix5, and 6.0.2 before iFix2 Rational Quality Manager (RQM) versions 4.0.x through 4.0.7 before iFix10, 5.0.x through 5.0.2 before iFix15, 6.0.x through 6.0.1 before iFix5, and 6.0.2 before iFix2 Rational Team Concert (RTC) versions 4.0.x through 4.0.7 before iFix10, 5.0.x through 5.0.2 before iFix15, 6.0.x through 6.0.1 before iFix5, and 6.0.2 before iFix2 Rational Requirements Composer (RRC) versions 4.0.x through 4.0.7 before iFix10 Rational DOORS Next Generation (RDNG) versions 4.0.x through 4.0.7 before iFix10, 5.0.x through 5.0.2 before iFix15, 6.0.x through 6.0.1 before iFix5, and 6.0.2 before iFix2 Rational Engineering Lifecycle Manager (RELM) versions 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7 before iFix1, 5.0.x through 5.0.2 before iFix1, and 6.0.x through 6.0.2 Rational Rhapsody Design Manager (Rhapsody DM) versions 4.0.x through 4.0.7 before iFix10, 5.0.x through 5.0.2 before iFix15, 6.0.x through 6.0.1 before iFix5, and 6.0.2 before iFix2 Rational Software Architect Design Manager (RSA DM) versions 4.0.x through 4.0.7 before iFix10, 5.0.x through 5.0.2 before iFix15, 6.0.x through 6.0.1 before iFix5, and 6.0.2 before iFix2
Description The issue allows local users to obtain sensitive information by leveraging weak encryption.
Recommendations For IBM Rational Collaborative Lifecycle Management (CLM) versions 4.0.x through 4.0.7 before iFix10, 5.0.x through 5.0.2 before iFix15, 6.0.x through 6.0.1 before iFix5, and 6.0.2 before iFix2, update to a version with the respective iFix applied. For Rational Quality Manager (RQM) versions 4.0.x through 4.0.7 before iFix10, 5.0.x through 5.0.2 before iFix15, 6.0.x through 6.0.1 before iFix5, and 6.0.2 before iFix2, update to a version with the respective iFix applied. For Rational Team Concert (RTC) versions 4.0.x through 4.0.7 before iFix10, 5.0.x through 5.0.2 before iFix15, 6.0.x through 6.0.1 before iFix5, and 6.0.2 before iFix2, update to a version with the respective iFix applied. For Rational Requirements Composer (RRC) versions 4.0.x through 4.0.7 before iFix10, update to a version with iFix10 applied. For Rational DOORS Next Generation (RDNG) versions 4.0.x through 4.0.7 before iFix10, 5.0.x through 5.0.2 before iFix15, 6.0.x through 6.0.1 before iFix5, and 6.0.2 before iFix2, update to a version with the respective iFix applied. For Rational Engineering Lifecycle Manager (RELM) versions 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7 before iFix1, 5.0.x through 5.0.2 before iFix1, and 6.0.x through 6.0.2, update to a version with the respective iFix applied. For Rational Rhapsody Design Manager (Rhapsody DM) versions 4.0.x through 4.0.7 before iFix10, 5.0.x through 5.0.2 before iFix15, 6.0.x through 6.0.1 before iFix5, and 6.0.2 before iFix2, update to a version with the respective iFix applied. For Rational Software Architect Design Manager (RSA DM) versions 4.0.x through 4.0.7 before iFix10, 5.0.x through 5.0.2 before iFix15, 6.0.x through 6.0.1 before iFix5, and 6.0.2 before iFix2, update to a version with the respective iFix applied.

Fix

Inadequate Encryption Strength

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7449

Affected Products

Ibm Rational Collaborative Lifecycle Management
Ibm Rational Doors Next Generation
Ibm Rational Engineering Lifecycle Manager
Ibm Rational Quality Manager
Ibm Rational Requirements Composer
Rational Rhapsody Design Manager
Ibm Rational Software Architect Design Manager
Ibm Rational Team Concert