3.3

CVE-2015-7449

IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Manager (RQM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Team Concert (RTC) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Requirements Composer (RRC) 4.0.x before 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7 before iFix1, 5.0.x before 5.0.2 iFix1, and 6.0.x before 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Software Architect Design Manager (RSA DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2 allow local users to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 108221.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmRational Collaborative Lifecycle Management Version >= 4.0.0 <= 6.0.2
IbmRational Quality Manager Version >= 4.0.0 <= 4.0.7
IbmRational Quality Manager Version5.0.0
IbmRational Quality Manager Version5.0.1
IbmRational Quality Manager Version5.0.2
IbmRational Quality Manager Version6.0.0
IbmRational Quality Manager Version6.0.1
IbmRational Quality Manager Version6.0.2
IbmRational Team Concert Version >= 4.0.0 <= 4.0.7
IbmRational Team Concert Version5.0.0
IbmRational Team Concert Version5.0.1
IbmRational Team Concert Version5.0.2
IbmRational Team Concert Version6.0.0
IbmRational Team Concert Version6.0.1
IbmRational Team Concert Version6.0.2
IbmRational Requirements Composer Version >= 4.0.0 <= 4.0.7
IbmRational Doors Next Generation Version >= 4.0.0 <= 4.0.7
IbmRational Engineering Lifecycle Manager Version >= 4.0.3 <= 4.0.7
IbmRational Rhapsody Design Manager Version >= 4.0 <= 4.0.7
IbmRational Software Architect Design Manager Version >= 4.0.0 <= 4.0.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.023
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.3 1.8 1.4
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.