First published: Wed Mar 18 2015(Updated: )
IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational DOORS Next Generation 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5; and other products, allows remote authenticated users to read the dashboards of arbitrary users via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational DOORS | =4.0.0 | |
IBM Rational DOORS | =4.0.1 | |
IBM Rational DOORS | =4.0.2 | |
IBM Rational DOORS | =4.0.3 | |
IBM Rational DOORS | =4.0.4 | |
IBM Rational DOORS | =4.0.5 | |
IBM Rational DOORS | =4.0.6 | |
IBM Rational DOORS | =4.0.7 | |
IBM Rational DOORS | =5.0 | |
IBM Rational DOORS | =5.0.1 | |
IBM Rational DOORS | =5.0.2 | |
IBM Rational Requirements Composer | =2.0 | |
IBM Rational Requirements Composer | =2.0.0.1 | |
IBM Rational Requirements Composer | =2.0.0.2 | |
IBM Rational Requirements Composer | =2.0.0.3 | |
IBM Rational Requirements Composer | =2.0.0.4 | |
IBM Rational Requirements Composer | =3.0 | |
IBM Rational Requirements Composer | =3.0.1 | |
IBM Rational Requirements Composer | =3.0.1.1 | |
IBM Rational Requirements Composer | =3.0.1.2 | |
IBM Rational Requirements Composer | =3.0.1.3 | |
IBM Rational Requirements Composer | =3.0.1.4 | |
IBM Rational Requirements Composer | =3.0.1.5 | |
IBM Rational Requirements Composer | =3.0.1.6 | |
IBM Collaborative Lifecycle Management | =3.0.0 | |
IBM Collaborative Lifecycle Management | =3.0.1 | |
IBM Collaborative Lifecycle Management | =3.0.1.1 | |
IBM Collaborative Lifecycle Management | =3.0.1.2 | |
IBM Collaborative Lifecycle Management | =3.0.1.3 | |
IBM Collaborative Lifecycle Management | =3.0.1.4 | |
IBM Collaborative Lifecycle Management | =3.0.1.5 | |
IBM Collaborative Lifecycle Management | =3.0.1.6 | |
IBM Collaborative Lifecycle Management | =4.0.0 | |
IBM Collaborative Lifecycle Management | =4.0.1 | |
IBM Collaborative Lifecycle Management | =4.0.2 | |
IBM Collaborative Lifecycle Management | =4.0.3 | |
IBM Collaborative Lifecycle Management | =4.0.4 | |
IBM Collaborative Lifecycle Management | =4.0.5 | |
IBM Collaborative Lifecycle Management | =4.0.6 | |
IBM Collaborative Lifecycle Management | =4.0.7 | |
IBM Collaborative Lifecycle Management | =5.0.0 | |
IBM Collaborative Lifecycle Management | =5.0.1 | |
IBM Collaborative Lifecycle Management | =5.0.2 | |
IBM Rational Team Concert | =2.0.0.1 | |
IBM Rational Team Concert | =2.0.0.2 | |
IBM Rational Team Concert | =3.0 | |
IBM Rational Team Concert | =3.0.1 | |
IBM Rational Team Concert | =3.0.1.1 | |
IBM Rational Team Concert | =3.0.1.2 | |
IBM Rational Team Concert | =3.0.1.3 | |
IBM Rational Team Concert | =3.0.1.4 | |
IBM Rational Team Concert | =3.0.1.5 | |
IBM Rational Team Concert | =3.0.1.6 | |
IBM Rational Team Concert | =4.0 | |
IBM Rational Team Concert | =4.0.0.1 | |
IBM Rational Team Concert | =4.0.0.2 | |
IBM Rational Team Concert | =4.0.1 | |
IBM Rational Team Concert | =4.0.2 | |
IBM Rational Team Concert | =4.0.3 | |
IBM Rational Team Concert | =4.0.4 | |
IBM Rational Team Concert | =4.0.5 | |
IBM Rational Team Concert | =4.0.6 | |
IBM Rational Team Concert | =4.0.7 | |
IBM Rational Team Concert | =5.0.0 | |
IBM Rational Team Concert | =5.0.1 | |
IBM Rational Team Concert | =5.0.2 | |
IBM Rational Quality Manager | =2.0 | |
IBM Rational Quality Manager | =2.0.0.1 | |
IBM Rational Quality Manager | =2.0.0.2 | |
IBM Rational Quality Manager | =2.0.1 | |
IBM Rational Quality Manager | =2.0.1.1 | |
IBM Rational Quality Manager | =3.0 | |
IBM Rational Quality Manager | =3.0.1 | |
IBM Rational Quality Manager | =3.0.1.1 | |
IBM Rational Quality Manager | =3.0.1.2 | |
IBM Rational Quality Manager | =3.0.1.3 | |
IBM Rational Quality Manager | =3.0.1.4 | |
IBM Rational Quality Manager | =3.0.1.5 | |
IBM Rational Quality Manager | =3.0.1.6 | |
IBM Rational Quality Manager | =4.0 | |
IBM Rational Quality Manager | =4.0.0.1 | |
IBM Rational Quality Manager | =4.0.0.2 | |
IBM Rational Quality Manager | =4.0.1 | |
IBM Rational Quality Manager | =4.0.2 | |
IBM Rational Quality Manager | =4.0.3 | |
IBM Rational Quality Manager | =4.0.4 | |
IBM Rational Quality Manager | =4.0.5 | |
IBM Rational Quality Manager | =4.0.7 | |
IBM Rational Quality Manager | =5.0.0 | |
IBM Rational Quality Manager | =5.0.1 | |
IBM Rational Quality Manager | =5.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6131 has a medium severity rating.
To fix CVE-2014-6131, upgrade to the latest fixed versions of the affected IBM Rational software products.
CVE-2014-6131 affects several IBM Rational products including Rational Jazz Team Server, Rational Quality Manager, and Rational Team Concert.
There are no direct workarounds for CVE-2014-6131; the recommended action is to update to the patched versions.
CVE-2014-6131 was published on September 17, 2014.