CVE-2018-1734: Infoleak
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 discloses sensitive information in error messages that may be used by a malicious user to orchestrate further attacks. IBM X-Force ID: 147838.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-1734.
What software products are affected by this vulnerability?
IBM Rational Collaborative Lifecycle Management, IBM Rational DOORS Next Generation, IBM Rational Engineering Lifecycle Manager, IBM Rational Quality Manager, IBM Rational Rhapsody Design Manager, IBM Rational Software Architect Design Manager, IBM Rational Team Concert, and IBM Rhapsody Model Manager are affected by this vulnerability.
How does this vulnerability manifest?
This vulnerability manifests as the disclosure of sensitive information in error messages.
What is the severity level of this vulnerability?
The severity level of this vulnerability is medium with a CVSS score of 4.3.
Are there any patches or updates available to fix this vulnerability?
Yes, IBM has released patches to address this vulnerability. Please refer to the IBM Security Bulletin for more information.