CVE-2016-2981: Infoleak
Published Mar 20, 2017
·Updated
An undisclosed vulnerability in the CLM applications in IBM Jazz Team Server may allow unauthorized access to user credentials. IBM Reference #: 1999965.
Affected Software
15 affected components
IBM Rational Collaborative Lifecycle Management=4.0
IBM Rational Collaborative Lifecycle Management=4.0.1
IBM Rational Collaborative Lifecycle Management=4.0.2
IBM Rational Collaborative Lifecycle Management=4.0.3
IBM Rational Collaborative Lifecycle Management=4.0.4
IBM Rational Collaborative Lifecycle Management=4.0.5
IBM Rational Collaborative Lifecycle Management=4.0.6
IBM Rational Collaborative Lifecycle Management=4.0.7
IBM Rational Collaborative Lifecycle Management=5.0
IBM Rational Collaborative Lifecycle Management=5.0.1
IBM Rational Collaborative Lifecycle Management=5.0.2
IBM Rational Collaborative Lifecycle Management=6.0
IBM Rational Collaborative Lifecycle Management=6.0.1
IBM Rational Collaborative Lifecycle Management=6.0.2
IBM Rational Collaborative Lifecycle Management=6.0.3
Remediation
Patch Available
Event History
Mar 20, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-2981?
CVE-2016-2981 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2016-2981?
To remediate CVE-2016-2981, it is recommended to apply the relevant security updates provided by IBM for the affected versions of IBM Collaborative Lifecycle Management.
3
Which products are affected by CVE-2016-2981?
CVE-2016-2981 affects various versions of IBM Rational Collaborative Lifecycle Management including 4.0 through 6.0.3.
4
What kind of access does CVE-2016-2981 allow?
CVE-2016-2981 may allow unauthorized access to user credentials within the affected CLM applications.
5
Is there a workaround for CVE-2016-2981?
There is no documented workaround for CVE-2016-2981; users should apply the available patches from IBM.