6.5
CVE-2016-2865
- EPSS 0.2%
- Published 15.07.2016 18:59:07
- Last modified 12.04.2025 10:46:40
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecycle Management 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 allows remote authenticated users to obtain sensitive information via a malformed request.
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Rational Team Concert Version5.0.0
Ibm ≫ Rational Team Concert Version5.0.1
Ibm ≫ Rational Team Concert Version5.0.2
Ibm ≫ Rational Collaborative Lifecycle Management Version5.0.0
Ibm ≫ Rational Collaborative Lifecycle Management Version5.0.1
Ibm ≫ Rational Collaborative Lifecycle Management Version5.0.2
Ibm ≫ Rational Team Concert Version6.0.0
Ibm ≫ Rational Team Concert Version6.0.1
Ibm ≫ Rational Collaborative Lifecycle Management Version6.0.0
Ibm ≫ Rational Collaborative Lifecycle Management Version6.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.2% | 0.393 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.