CVE-2019-4601: Medium severity IBM Rational Quality Manager vulnerability
IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to obtain sensitive information from a stack trace that could aid in further attacks against the system.
Other sources
IBM Quality Manager (RQM) could allow an authenticated user to obtain sensitive information from a stack trace that could aid in further attacks against the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4601?
The severity of CVE-2019-4601 is medium with a severity value of 4.3.
How does CVE-2019-4601 impact IBM Quality Manager (RQM)?
CVE-2019-4601 allows an authenticated user to obtain sensitive information from a stack trace in IBM Quality Manager (RQM) versions 6.02, 6.06, and 6.0.6.1.
How can an attacker exploit CVE-2019-4601?
An attacker can exploit CVE-2019-4601 by using the obtained sensitive information from the stack trace to launch further attacks against the system.
Which versions of IBM Quality Manager (RQM) are affected by CVE-2019-4601?
IBM Quality Manager (RQM) versions 6.02, 6.06, 6.0.6, and 6.0.6.1 are affected by CVE-2019-4601.
Is there a fix for CVE-2019-4601?
Yes, IBM has released a fix for CVE-2019-4601. It is recommended to update to the latest version of IBM Quality Manager (RQM) to mitigate the vulnerability.