4.3
CVE-2018-1606
- EPSS 0.18%
- Published 06.11.2018 16:29:00
- Last modified 21.11.2024 04:00:04
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
IBM Jazz based applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational DOORS Next Generation 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Quality Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Rhapsody Design Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Software Architect Design Manager 5.0 through 5.02 and 6.0 through 6.0.1, IBM Rational Team Concert 5.0 through 5.02 and 6.0 through 6.0.6) could allow an authenticated user to obtain sensitive information from an error message that could be used in further attacks against the system. IBM X-Force ID: 143796.
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Rational Collaborative Lifecycle Management Version >= 5.0.0 <= 6.0.6
Ibm ≫ Rational Doors Next Generation Version >= 5.0.0 <= 5.0.2
Ibm ≫ Rational Doors Next Generation Version >= 6.0.0 <= 6.0.6
Ibm ≫ Rational Engineering Lifecycle Manager Version >= 5.0.0 <= 5.0.2
Ibm ≫ Rational Engineering Lifecycle Manager Version >= 6.0.0 <= 6.0.6
Ibm ≫ Rational Quality Manager Version >= 5.0.0 <= 5.0.2
Ibm ≫ Rational Quality Manager Version >= 6.0.0 <= 6.0.6
Ibm ≫ Rational Rhapsody Design Manager Version >= 5.0.0 <= 5.0.2
Ibm ≫ Rational Rhapsody Design Manager Version >= 6.0.0 <= 6.0.6
Ibm ≫ Rational Software Architect Design Manager Version >= 5.0.0 <= 5.0.2
Ibm ≫ Rational Software Architect Design Manager Version >= 6.0.0 <= 6.0.1
Ibm ≫ Rational Team Concert Version >= 5.0.0 <= 5.0.2
Ibm ≫ Rational Team Concert Version >= 6.0.0 <= 6.0.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.18% | 0.37 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
psirt@us.ibm.com | 4.3 | 2.8 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.