First published: Fri Jul 15 2016(Updated: )
The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecycle Management 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 allows remote authenticated users to obtain sensitive information via a malformed request.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational Team Concert | =5.0.0 | |
IBM Rational Team Concert | =5.0.1 | |
IBM Rational Team Concert | =5.0.2 | |
IBM Collaborative Lifecycle Management | =5.0.0 | |
IBM Collaborative Lifecycle Management | =5.0.1 | |
IBM Collaborative Lifecycle Management | =5.0.2 | |
IBM Rational Team Concert | =6.0.0 | |
IBM Rational Team Concert | =6.0.1 | |
IBM Collaborative Lifecycle Management | =6.0.0 | |
IBM Collaborative Lifecycle Management | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2865 has been classified as a medium severity vulnerability.
To remediate CVE-2016-2865, upgrade to IBM Rational Team Concert version 5.0.2 iFix14, 6.0.1 iFix5 or higher.
CVE-2016-2865 affects IBM Rational Team Concert versions 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5, as well as Rational Collaborative Lifecycle Management versions 5.x and 6.x prior to the specified fixes.
CVE-2016-2865 allows remote authenticated users to obtain sensitive information through a malformed request.
Yes, immediate action is recommended to patch CVE-2016-2865 to protect sensitive information from unauthorized access.