CVE-2016-6060: Infoleak
Published Feb 15, 2017
·Updated
An undisclosed vulnerability in IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 could allow a JazzGuest user to see project names. IBM Reference #: 1995547.
Affected Software
14 affected components
IBM Rational DOORS Next Generation=5.0
IBM Rational DOORS Next Generation=5.0.0
IBM Rational DOORS Next Generation=5.0.1
IBM Rational DOORS Next Generation=5.0.2
IBM Rational DOORS Next Generation=6.0.0
IBM Rational DOORS Next Generation=6.0.1
IBM Rational DOORS Next Generation=6.0.2
IBM Rational Requirements Composer=4.0.1
IBM Rational Requirements Composer=4.0.2
IBM Rational Requirements Composer=4.0.3
IBM Rational Requirements Composer=4.0.4
IBM Rational Requirements Composer=4.0.5
IBM Rational Requirements Composer=4.0.6
IBM Rational Requirements Composer=4.0.7
Remediation
Patch Available
Event History
Feb 15, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6060?
The severity of CVE-2016-6060 is classified as low.
2
How do I fix CVE-2016-6060?
To fix CVE-2016-6060, update IBM Rational DOORS Next Generation to the latest version available.
3
Which versions of software are affected by CVE-2016-6060?
CVE-2016-6060 affects IBM Rational DOORS Next Generation versions 4.0, 5.0, and 6.0 as well as certain versions of IBM Rational Requirements Composer.
4
Who is affected by CVE-2016-6060?
A JazzGuest user may be affected by CVE-2016-6060 by being able to see project names.
5
What is the nature of CVE-2016-6060?
CVE-2016-6060 is an undisclosed vulnerability allowing unauthorized visibility of project names.