CVE-2014-0844: Low severity IBM Rational Requirements Composer vulnerability
Unspecified vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to read arbitrary data via unknown vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Rational Requirements Composerto a version that resolves this vulnerability.Fixed in 3.0.1.6 iFix2 - Upgrade
Upgrade
IBM Rational Requirements Composerto a version that resolves this vulnerability.Fixed in 4.0.6 - Upgrade
Upgrade
Rational DOORS Next Generationto a version that resolves this vulnerability.Fixed in 4.0.6
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0844?
CVE-2014-0844 has a moderate severity rating as it allows remote authenticated users to read arbitrary data.
How do I fix CVE-2014-0844?
To fix CVE-2014-0844, you should upgrade to IBM Rational Requirements Composer version 3.0.1.6 or 4.0.6 or later.
Which versions are affected by CVE-2014-0844?
CVE-2014-0844 affects IBM Rational Requirements Composer versions 3.x before 3.0.1.6 and 4.x before 4.0.6, as well as IBM Rational DOORS Next Generation 4.x before 4.0.6.
What are the potential impacts of CVE-2014-0844 if exploited?
If exploited, CVE-2014-0844 could lead to unauthorized access to sensitive information by authenticated users.
Is there a workaround for CVE-2014-0844?
Currently, the recommended approach is to apply the patches or updates rather than relying on workarounds for CVE-2014-0844.