First published: Mon Oct 25 2021(Updated: )
IBM Jazz Foundation stores user credentials in clear text which can be read by an authenticated user.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM CLM | <=6.0.6.1 | |
IBM CLM | <=6.0.6 | |
IBM ELM | <=7.0.2 | |
IBM ELM | <=7.0 | |
IBM ELM | <=7.0.1 | |
IBM Engineering Requirements Quality Assistant | <=1.0 | |
IBM Engineering Requirements Quality Assistant On-Premises | <=All | |
IBM EWM | <=7.0.2 | |
IBM EWM | <=7.0.1 | |
IBM RTC | <=6.0.2 | |
IBM RTC | <=6.0.6.1 | |
IBM EWM | <=7.0 | |
IBM RTC | <=6.0.6 | |
IBM Engineering Systems Design Rhapsody | <=All | |
IBM DOORS Next | <=7.0.2 | |
IBM DOORS Next | <=7.0 | |
IBM DOORS Next | <=7.0.1 | |
IBM RDNG | <=6.0.6.1 | |
IBM RDNG | <=6.0.6 | |
IBM Engineering Lifecycle Optimization | =7.0 | |
IBM Engineering Lifecycle Optimization | =7.0.1 | |
IBM Engineering Lifecycle Optimization | =7.0.2 | |
IBM Engineering Workflow Management | =7.0 | |
IBM Engineering Workflow Management | =7.0.1 | |
IBM Engineering Workflow Management | =7.0.2 | |
IBM Rational Collaborative Lifecycle Management | =6.0.6 | |
IBM Rational Collaborative Lifecycle Management | =6.0.6.1 | |
IBM Rational DOORS Next Generation | =6.0.6 | |
IBM Rational DOORS Next Generation | =6.0.6.1 | |
IBM Rational DOORS Next Generation | =7.0 | |
IBM Rational DOORS Next Generation | =7.0.1 | |
IBM Rational DOORS Next Generation | =7.0.2 | |
IBM Rational Engineering Lifecycle Manager | =7.0 | |
IBM Rational Team Concert | =6.0.2 | |
IBM Rational Team Concert | =6.0.6 | |
IBM Rational Team Concert | =6.0.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2021-29786.
The severity level of CVE-2021-29786 is medium.
The affected software products are IBM Engineering Lifecycle Optimization 7.0, IBM Engineering Workflow Management 7.0, IBM Rational Collaborative Lifecycle Management 6.0.6, IBM Rational DOORS Next Generation 6.0.6 and 7.0, IBM Rational Engineering Lifecycle Manager 7.0, and IBM Rational Team Concert 6.0.2 and 6.0.6.
An authenticated user can exploit CVE-2021-29786 by reading user credentials that are stored in clear text.
Yes, IBM has released a fix for CVE-2021-29786. Please refer to the IBM Security Bulletin for more information.