First published: Fri Mar 23 2018(Updated: )
IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially crafted URL. IBM X-Force ID: 132625.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational Collaborative Lifecycle Management | >=4.0.0<=6.0.5 | |
IBM Rational Quality Manager | >=4.0.0<=4.0.7 | |
IBM Rational Quality Manager | >=6.0.0<=6.0.5 | |
IBM Rational Quality Manager | =5.0.0 | |
IBM Rational Quality Manager | =5.0.1 | |
IBM Rational Quality Manager | =5.0.2 | |
IBM Rational Team Concert | >=4.0.0<=4.0.7 | |
IBM Rational Team Concert | >=6.0.0<=6.0.5 | |
IBM Rational Team Concert | =5.0.0 | |
IBM Rational Team Concert | =5.0.1 | |
IBM Rational Team Concert | =5.0.2 | |
IBM Rational DOORS Next Generation | >=4.0.1<=4.0.7 | |
IBM Rational DOORS Next Generation | >=6.0.0<=6.0.5 | |
IBM Rational DOORS Next Generation | =5.0.0 | |
IBM Rational DOORS Next Generation | =5.0.1 | |
IBM Rational DOORS Next Generation | =5.0.2 | |
IBM Rational Engineering Lifecycle Manager | >=4.0.3<=4.0.7 | |
IBM Rational Engineering Lifecycle Manager | >=6.0.0<=6.0.5 | |
IBM Rational Engineering Lifecycle Manager | =5.0.0 | |
IBM Rational Engineering Lifecycle Manager | =5.0.1 | |
IBM Rational Engineering Lifecycle Manager | =5.0.2 | |
IBM Rational Rhapsody Design Manager | >=4.0<=4.0.7 | |
IBM Rational Rhapsody Design Manager | >=6.0.0<=6.0.5 | |
IBM Rational Rhapsody Design Manager | =5.0.0 | |
IBM Rational Rhapsody Design Manager | =5.0.1 | |
IBM Rational Rhapsody Design Manager | =5.0.2 | |
IBM Rational Software Architect Design Manager | >=4.0.0<=4.0.7 | |
IBM Rational Software Architect Design Manager | =5.0.0 | |
IBM Rational Software Architect Design Manager | =5.0.1 | |
IBM Rational Software Architect Design Manager | =5.0.2 | |
IBM Rational Software Architect Design Manager | =6.0.0 | |
IBM Rational Software Architect Design Manager | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2017-1602.
The affected software includes IBM Rational Collaborative Lifecycle Management, IBM Rational Quality Manager, IBM Rational Team Concert, IBM Rational DOORS Next Generation, IBM Rational Engineering Lifecycle Manager, IBM Rational Rhapsody Design Manager, and IBM Rational Software Architect Design Manager.
The severity of CVE-2017-1602 vulnerability is medium with a severity score of 4.3.
An authenticated user can exploit this vulnerability by using a specially crafted URL to access settings they should not be able to.
You can find more information about this vulnerability at the following references: [IBM Support](http://www.ibm.com/support/docview.wss?uid=swg22014815), [SecurityFocus](http://www.securityfocus.com/bid/103477), [IBM X-Force](https://exchange.xforce.ibmcloud.com/vulnerabilities/132625).