CVE-2015-7484: Infoleak
IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1 and 4.0 before 4.0.7 iFix10 allow remote authenticated users with access to lifecycle projects to obtain sensitive information by sending a crafted URL to the Lifecycle Query Engine. IBM X-Force ID: 108619.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7484?
CVE-2015-7484 has a medium severity rating due to the risk of sensitive information exposure.
How do I fix CVE-2015-7484?
To fix CVE-2015-7484, upgrade to IBM Rational Engineering Lifecycle Manager version 3.0.1.6 iFix7 Interim Fix 1 or 4.0.7 iFix10.
Who is affected by CVE-2015-7484?
CVE-2015-7484 affects users of IBM Rational Engineering Lifecycle Manager versions prior to 3.0.1.6 and 4.0.7.
What type of attack does CVE-2015-7484 enable?
CVE-2015-7484 allows remote authenticated users to gain unauthorized access to sensitive information via crafted URLs.
Is there a workaround for CVE-2015-7484 before applying the fix?
There are no known workarounds for CVE-2015-7484; the recommended action is to apply the available updates.