CVE-2015-0121: Low severity ibm rational requirements composer vulnerability
IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next Generation (RDNG) 4.0 through 4.0.7 and 5.0 through 5.0.2, when LTPA single sign on is used with WebSphere Application Server, do not terminate a Requirements Management (RM) session upon LTPA token expiration, which allows remote attackers to obtain access by leveraging an unattended workstation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0121?
CVE-2015-0121 is rated as having medium severity due to its impact on session management.
How do I fix CVE-2015-0121?
To fix CVE-2015-0121, upgrade to the latest versions of IBM Rational Requirements Composer and IBM Rational DOORS Next Generation that are not affected by the vulnerability.
What versions of IBM Rational Requirements Composer are affected by CVE-2015-0121?
CVE-2015-0121 affects IBM Rational Requirements Composer versions 3.0 through 3.0.1.6 and 4.0 through 4.0.7.
What versions of IBM Rational DOORS Next Generation are affected by CVE-2015-0121?
CVE-2015-0121 affects IBM Rational DOORS Next Generation versions 4.0 through 4.0.7 and 5.0 through 5.0.2.
What is the impact of CVE-2015-0121?
The impact of CVE-2015-0121 is that it may allow unauthorized access to requirements management sessions under certain conditions.