First published: Fri Mar 08 2019(Updated: )
IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 could allow a malicious user to be allowed to view any view if he knows the URL link of a the view, and access information that should not be able to see. IBM X-Force ID: 153120.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Engineering Lifecycle Manager | >=5.0<=5.0.2 | |
IBM Engineering Lifecycle Manager | >=6.0<=6.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1929 is considered a medium severity vulnerability.
To fix CVE-2018-1929, you should upgrade IBM Rational Engineering Lifecycle Manager to the latest version that patches this vulnerability.
CVE-2018-1929 affects users of IBM Rational Engineering Lifecycle Manager versions 5.0 through 6.0.6.
CVE-2018-1929 allows a malicious user to view restricted content if they know the URL of the view.
Currently, no specific workarounds are provided for CVE-2018-1929, so upgrading is recommended.