CVE-2017-1239: Infoleak
Published Jul 6, 2018
·Updated
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID: 124357.
Affected Software
3 affected components
IBM Rational Quality Manager>=5.0<=5.0.2
IBM Rational Quality Manager>=6.0<=6.0.5
IBM Rational Collaborative Lifecycle Management>=5.0.0<=6.0.3
Remediation
Patch Available
Event History
Jul 6, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this IBM Quality Manager vulnerability?
The vulnerability ID for this IBM Quality Manager vulnerability is CVE-2017-1239.
2
What is the severity rating of CVE-2017-1239?
The severity rating of CVE-2017-1239 is medium, with a score of 5.3.
3
How can this vulnerability be exploited?
This vulnerability can be exploited by revealing sensitive information in HTTP 500 Internal Server Error responses.
4
What versions of IBM Quality Manager are affected by CVE-2017-1239?
IBM Quality Manager versions 5.0.x and 6.0 through 6.0.5 are affected by CVE-2017-1239.
5
Is there a fix or patch available for CVE-2017-1239?
Yes, IBM has provided fixes for this vulnerability. Please refer to the IBM support document for more information.