CVE-2018-1929: Infoleak
Published Mar 8, 2019
·Updated
IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 could allow a malicious user to be allowed to view any view if he knows the URL link of a the view, and access information that should not be able to see. IBM X-Force ID: 153120.
Affected Software
2 affected components
IBM Rational Engineering Lifecycle Manager>=5.0<=5.0.2
IBM Rational Engineering Lifecycle Manager>=6.0<=6.0.6
Remediation
Patch Available
Event History
Mar 14, 2019
CVE Published
10:29 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1929?
CVE-2018-1929 is considered a medium severity vulnerability.
2
How do I fix CVE-2018-1929?
To fix CVE-2018-1929, you should upgrade IBM Rational Engineering Lifecycle Manager to the latest version that patches this vulnerability.
3
Who is affected by CVE-2018-1929?
CVE-2018-1929 affects users of IBM Rational Engineering Lifecycle Manager versions 5.0 through 6.0.6.
4
What kind of access does CVE-2018-1929 allow?
CVE-2018-1929 allows a malicious user to view restricted content if they know the URL of the view.
5
Is there a workaround for CVE-2018-1929?
Currently, no specific workarounds are provided for CVE-2018-1929, so upgrading is recommended.