CVE-2017-1524: Infoleak
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request that could be used to aid future attacks. IBM X-Force ID: 129970.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2017-1524.
What is the severity level of CVE-2017-1524?
The severity level of CVE-2017-1524 is medium (4.3).
Which software is affected by CVE-2017-1524?
IBM Rational Collaborative Lifecycle Management 5.0 and 6.0, IBM Rational Quality Manager, IBM Rational Team Concert, IBM Rational DOORS Next Generation, IBM Rational Engineering Lifecycle Manager, IBM Rational Rhapsody Design Manager, IBM Rational Software Architect Design Manager.
What is the impact of CVE-2017-1524?
An authenticated user may obtain sensitive information from a specially crafted HTTP request that could be used to aid future attacks.
Are there any references available for CVE-2017-1524?
Yes, here are some references: [IBM support document](http://www.ibm.com/support/docview.wss?uid=swg22014815), [SecurityFocus](http://www.securityfocus.com/bid/103477), [IBM X-Force ID](https://exchange.xforce.ibmcloud.com/vulnerabilities/129970).