First published: Tue Jul 10 2018(Updated: )
IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational Collaborative Lifecycle Management | >=5.0<=6.0.5 | |
IBM Rational Team Concert | >=5.0<=5.0.2 | |
IBM Rational Team Concert | >=6.0.0<=6.0.5 | |
IBM Rational DOORS Next Generation | >=5.0<=5.0.2 | |
IBM Rational DOORS Next Generation | >=6.0.0<=6.0.5 | |
IBM Rational Quality Manager | >=5.0<=5.0.2 | |
IBM Rational Quality Manager | >=6.0.0<=6.0.5 | |
IBM Rational Rhapsody Design Manager | >=5.0<=5.0.2 | |
IBM Rational Rhapsody Design Manager | >=6.0.0<=6.0.5 | |
IBM Rational Software Architect Design Manager | >=5.0<=5.0.2 | |
IBM Rational Software Architect Design Manager | >=6.0<=6.0.1 | |
IBM Rational Engineering Lifecycle Manager | >=5.0<=5.0.2 | |
IBM Rational Engineering Lifecycle Manager | >=6.0.0<=6.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2018-1492.
The affected products include IBM Rational Collaborative Lifecycle Management, IBM Rational Team Concert, IBM Rational DOORS Next Generation, IBM Rational Quality Manager, IBM Rational Rhapsody Design Manager, IBM Rational Software Architect Design Manager, and IBM Rational Engineering Lifecycle Manager.
The severity of CVE-2018-1492 is medium, with a CVSS score of 6.8.
An attacker with physical access to the system can log in as another user due to the server's failure to properly log out from the previous session.
Yes, IBM has released fixes to address this vulnerability. Please refer to the IBM Security Bulletin for specific details.