First published: Mon Oct 25 2021(Updated: )
IBM Jazz Foundation stores user credentials in clear text which can be read by an authenticated user.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Engineering Lifecycle Optimization | =7.0 | |
IBM Engineering Lifecycle Optimization | =7.0.1 | |
IBM Engineering Lifecycle Optimization | =7.0.2 | |
IBM Engineering Workflow Management (EWM) | =7.0 | |
IBM Engineering Workflow Management (EWM) | =7.0.1 | |
IBM Engineering Workflow Management (EWM) | =7.0.2 | |
IBM Collaborative Lifecycle Management | =6.0.6 | |
IBM Collaborative Lifecycle Management | =6.0.6.1 | |
IBM Engineering Requirements Management DOORS Next Generation | =6.0.6 | |
IBM Engineering Requirements Management DOORS Next Generation | =6.0.6.1 | |
IBM Engineering Requirements Management DOORS Next Generation | =7.0 | |
IBM Engineering Requirements Management DOORS Next Generation | =7.0.1 | |
IBM Engineering Requirements Management DOORS Next Generation | =7.0.2 | |
IBM Engineering Lifecycle Manager | =7.0 | |
IBM Rational Team Concert | =6.0.2 | |
IBM Rational Team Concert | =6.0.6 | |
IBM Rational Team Concert | =6.0.6.1 | |
IBM Engineering Lifecycle Management | <=6.0.6.1 | |
IBM Engineering Lifecycle Management | <=6.0.6 | |
IBM Engineering Lifecycle Management (ELM) | <=7.0.2 | |
IBM Engineering Lifecycle Management (ELM) | <=7.0 | |
IBM Engineering Lifecycle Management (ELM) | <=7.0.1 | |
IBM Engineering Requirements Quality Assistant On-Premises | <=1.0 | |
IBM Engineering Requirements Quality Assistant | <=All | |
IBM Engineering Workflow Management (EWM) | <=7.0.2 | |
IBM Engineering Workflow Management (EWM) | <=7.0.1 | |
IBM Rational Team Concert | <=6.0.2 | |
IBM Rational Team Concert | <=6.0.6.1 | |
IBM Engineering Workflow Management (EWM) | <=7.0 | |
IBM Rational Team Concert | <=6.0.6 | |
IBM Rhapsody | <=All | |
IBM Rational DOORS Next Generation | <=7.0.2 | |
IBM Rational DOORS Next Generation | <=7.0 | |
IBM Rational DOORS Next Generation | <=7.0.1 | |
IBM Rational DOORS Next Generation | <=6.0.6.1 | |
IBM Rational DOORS Next Generation | <=6.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2021-29786.
The severity level of CVE-2021-29786 is medium.
The affected software products are IBM Engineering Lifecycle Optimization 7.0, IBM Engineering Workflow Management 7.0, IBM Rational Collaborative Lifecycle Management 6.0.6, IBM Rational DOORS Next Generation 6.0.6 and 7.0, IBM Rational Engineering Lifecycle Manager 7.0, and IBM Rational Team Concert 6.0.2 and 6.0.6.
An authenticated user can exploit CVE-2021-29786 by reading user credentials that are stored in clear text.
Yes, IBM has released a fix for CVE-2021-29786. Please refer to the IBM Security Bulletin for more information.