CVE-2016-6040: Medium severity IBM Rational Collaborative Lifecycle Management vulnerability
Published Feb 1, 2017
·Updated
IBM Jazz Foundation could allow an authenticated user to take over a previously logged in user due to session expiration not being enforced.
Affected Software
14 affected components
IBM Rational Collaborative Lifecycle Management=4.0.0
IBM Rational Collaborative Lifecycle Management=4.0.1
IBM Rational Collaborative Lifecycle Management=4.0.2
IBM Rational Collaborative Lifecycle Management=4.0.3
IBM Rational Collaborative Lifecycle Management=4.0.4
IBM Rational Collaborative Lifecycle Management=4.0.5
IBM Rational Collaborative Lifecycle Management=4.0.6
IBM Rational Collaborative Lifecycle Management=4.0.7
IBM Rational Collaborative Lifecycle Management=5.0.0
IBM Rational Collaborative Lifecycle Management=5.0.1
IBM Rational Collaborative Lifecycle Management=5.0.2
IBM Rational Collaborative Lifecycle Management=6.0.0
IBM Rational Collaborative Lifecycle Management=6.0.1
IBM Rational Collaborative Lifecycle Management=6.0.2
Remediation
Patch Available
Event History
Feb 1, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Data Sourced
via NVD·08:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 13, 58332
Event
10:37 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-6040?
CVE-2016-6040 is classified as a medium severity vulnerability.
2
How do I fix CVE-2016-6040?
To fix CVE-2016-6040, update to the latest version of IBM Rational Collaborative Lifecycle Management.
3
Who is affected by CVE-2016-6040?
CVE-2016-6040 affects authenticated users of IBM Rational Collaborative Lifecycle Management versions 4.0.0 to 6.0.2.
4
What type of vulnerability is CVE-2016-6040?
CVE-2016-6040 is a session management vulnerability allowing session takeover.
5
Can CVE-2016-6040 be exploited remotely?
CVE-2016-6040 requires authenticated access, thus it cannot be exploited remotely without prior authentication.