CVE-2015-4946

LOW

IBM Rational Quality Manager - Unauthenticated Access Restriction Bypass

Title source: llm
STIX 2.1

Description

Rational LifeCycle Project Administration in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Team Concert (RTC) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Requirements Composer (RRC) 3.x before 3.0.1.6 IF7 and 4.x before 4.0.7 IF9; Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF9, and 6.x before 6.0.1; Rational Engineering Lifecycle Manager (RELM) 4.x through 4.0.7, 5.x through 5.0.2, and 6.x before 6.0.1; Rational Rhapsody Design Manager (DM) 4.x through 4.0.7, 5.x through 5.0.2, and 6.x before 6.0.1; and Rational Software Architect Design Manager (DM) 4.x through 4.0.7, 5.x through 5.0.2, and 6.x before 6.0.1 allows local users to bypass intended access restrictions via unspecified vectors.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21973404

Scores

CVSS v3 3.3
EPSS 0.0030
EPSS Percentile 22.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-264
Status published
Products (50)
ibm/rational_collaborative_lifecycle_management 3.0.1
ibm/rational_collaborative_lifecycle_management 4.0.1
ibm/rational_collaborative_lifecycle_management 4.0.2
ibm/rational_collaborative_lifecycle_management 4.0.3
ibm/rational_collaborative_lifecycle_management 4.0.4
ibm/rational_collaborative_lifecycle_management 4.0.5
ibm/rational_collaborative_lifecycle_management 4.0.6
ibm/rational_collaborative_lifecycle_management 4.0.7
ibm/rational_collaborative_lifecycle_management 5.0
ibm/rational_collaborative_lifecycle_management 5.0.1
... and 40 more
Published Jan 03, 2016
Tracked Since Feb 18, 2026