First published: Thu Jun 27 2019(Updated: )
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 discloses sensitive information in error messages that may be used by a malicious user to orchestrate further attacks. IBM X-Force ID: 147838.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational Collaborative Lifecycle Management | >=6.0<=6.0.6.1 | |
IBM Rational DOORS Next Generation | >=6.0<=6.0.6.1 | |
IBM Rational Engineering Lifecycle Manager | >=6.0<=6.0.6.1 | |
IBM Rational Quality Manager | >=6.0<=6.0.6.1 | |
IBM Rational Rhapsody Design Manager | >=6.0<=6.0.6.1 | |
IBM Rational Software Architect Design Manager | >=6.0<=6.0.1 | |
IBM Rational Team Concert | >=6.0<=6.0.6.1 | |
IBM Rhapsody Model Manager | >=6.0.5<=6.0.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-1734.
IBM Rational Collaborative Lifecycle Management, IBM Rational DOORS Next Generation, IBM Rational Engineering Lifecycle Manager, IBM Rational Quality Manager, IBM Rational Rhapsody Design Manager, IBM Rational Software Architect Design Manager, IBM Rational Team Concert, and IBM Rhapsody Model Manager are affected by this vulnerability.
This vulnerability manifests as the disclosure of sensitive information in error messages.
The severity level of this vulnerability is medium with a CVSS score of 4.3.
Yes, IBM has released patches to address this vulnerability. Please refer to the IBM Security Bulletin for more information.