First published: Tue Jan 16 2018(Updated: )
IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1 and 4.0 before 4.0.7 iFix10 allow remote authenticated users with access to lifecycle projects to obtain sensitive information by sending a crafted URL to the Lifecycle Query Engine. IBM X-Force ID: 108619.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Engineering Lifecycle Manager | >=3.0<=3.0.1.6 | |
IBM Engineering Lifecycle Manager | >=4.0<=4.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7484 has a medium severity rating due to the risk of sensitive information exposure.
To fix CVE-2015-7484, upgrade to IBM Rational Engineering Lifecycle Manager version 3.0.1.6 iFix7 Interim Fix 1 or 4.0.7 iFix10.
CVE-2015-7484 affects users of IBM Rational Engineering Lifecycle Manager versions prior to 3.0.1.6 and 4.0.7.
CVE-2015-7484 allows remote authenticated users to gain unauthorized access to sensitive information via crafted URLs.
There are no known workarounds for CVE-2015-7484; the recommended action is to apply the available updates.