7.8

CVE-2015-7440

IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Team Concert (RTC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Requirements Composer (RRC) 3.0.x before 3.0.1.6 iFix7 Interim Fix 1 and 4.0.x before 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6, and 4.0.7 before iFix10, 5.0.x before 5.0.2 iFix1, and 6.0.x before 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; and Rational Software Architect Design Manager (RSA DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4 might allow local users to gain privileges via unspecified vectors. IBM X-Force ID: 108098.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Rational Collaborative Lifecycle Management Version >= 3.0.1 <= 6.0.1
Ibm ≫ Rational Quality Manager Version >= 3.0 <= 3.0.1.6
Ibm ≫ Rational Quality Manager Version >= 4.0 <= 4.0.7
Ibm ≫ Rational Quality Manager Version 5.0
Ibm ≫ Rational Quality Manager Version 5.0.1
Ibm ≫ Rational Quality Manager Version 5.0.2
Ibm ≫ Rational Quality Manager Version 6.0
Ibm ≫ Rational Quality Manager Version 6.0.1
Ibm ≫ Rational Team Concert Version >= 3.0 <= 3.0.6
Ibm ≫ Rational Team Concert Version >= 4.0 <= 4.0.7
Ibm ≫ Rational Team Concert Version 5.0
Ibm ≫ Rational Team Concert Version 5.0.1
Ibm ≫ Rational Team Concert Version 5.0.2
Ibm ≫ Rational Team Concert Version 6.0
Ibm ≫ Rational Team Concert Version 6.0.1
Ibm ≫ Rational Requirements Composer Version >= 3.0 <= 3.0.1.6
Ibm ≫ Rational Requirements Composer Version >= 4.0 <= 4.0.7
Ibm ≫ Rational Doors Next Generation Version >= 4.0 <= 4.0.7
Ibm ≫ Rational Engineering Lifecycle Manager Version >= 4.0.3 <= 4.0.7
Ibm ≫ Rational Rhapsody Design Manager Version >= 4.0 <= 4.0.7
Ibm ≫ Rational Software Architect Design Manager Version >= 4.0 <= 4.0.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.234
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www-01.ibm.com/support/docview.wss?uid=swg21982747
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/108098
Vendor Advisory
VDB Entry