First published: Tue Mar 04 2014(Updated: )
Unspecified vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to read arbitrary data via unknown vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational Requirements Composer | =3.0.1 | |
IBM Rational Requirements Composer | =3.0.1.1 | |
IBM Rational Requirements Composer | =3.0.1.2 | |
IBM Rational Requirements Composer | =3.0.1.3 | |
IBM Rational Requirements Composer | =3.0.1.4 | |
IBM Rational Requirements Composer | =3.0.1.5 | |
IBM Rational Requirements Composer | =3.0.1.6 | |
IBM Rational Requirements Composer | =4.0.0 | |
IBM Rational Requirements Composer | =4.0.0.1 | |
IBM Rational Requirements Composer | =4.0.0.2 | |
IBM Rational Requirements Composer | =4.0.1 | |
IBM Rational Requirements Composer | =4.0.2 | |
IBM Rational Requirements Composer | =4.0.3 | |
IBM Rational Requirements Composer | =4.0.4 | |
IBM Rational Requirements Composer | =4.0.5 | |
IBM Engineering Requirements Management DOORS Next Generation | =4.0.0 | |
IBM Engineering Requirements Management DOORS Next Generation | =4.0.1 | |
IBM Engineering Requirements Management DOORS Next Generation | =4.0.2 | |
IBM Engineering Requirements Management DOORS Next Generation | =4.0.3 | |
IBM Engineering Requirements Management DOORS Next Generation | =4.0.4 | |
IBM Engineering Requirements Management DOORS Next Generation | =4.0.5 | |
=3.0.1 | ||
=3.0.1.1 | ||
=3.0.1.2 | ||
=3.0.1.3 | ||
=3.0.1.4 | ||
=3.0.1.5 | ||
=3.0.1.6 | ||
=4.0.0 | ||
=4.0.0.1 | ||
=4.0.0.2 | ||
=4.0.1 | ||
=4.0.2 | ||
=4.0.3 | ||
=4.0.4 | ||
=4.0.5 | ||
=4.0.0 | ||
=4.0.1 | ||
=4.0.2 | ||
=4.0.3 | ||
=4.0.4 | ||
=4.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0844 has a moderate severity rating as it allows remote authenticated users to read arbitrary data.
To fix CVE-2014-0844, you should upgrade to IBM Rational Requirements Composer version 3.0.1.6 or 4.0.6 or later.
CVE-2014-0844 affects IBM Rational Requirements Composer versions 3.x before 3.0.1.6 and 4.x before 4.0.6, as well as IBM Rational DOORS Next Generation 4.x before 4.0.6.
If exploited, CVE-2014-0844 could lead to unauthorized access to sensitive information by authenticated users.
Currently, the recommended approach is to apply the patches or updates rather than relying on workarounds for CVE-2014-0844.