CVE-2015-7449

LOW

IBM Rational <4.0.7-6.0.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Manager (RQM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Team Concert (RTC) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Requirements Composer (RRC) 4.0.x before 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7 before iFix1, 5.0.x before 5.0.2 iFix1, and 6.0.x before 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Software Architect Design Manager (RSA DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2 allow local users to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 108221.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21985143
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/108221

Scores

CVSS v3 3.3
EPSS 0.0013
EPSS Percentile 3.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-326 CWE-200
Status published
Products (44)
ibm/rational_collaborative_lifecycle_management 4.0.0 - 6.0.2
ibm/rational_doors_next_generation 5.0.0
ibm/rational_doors_next_generation 5.0.1
ibm/rational_doors_next_generation 5.0.2
ibm/rational_doors_next_generation 6.0.0
ibm/rational_doors_next_generation 6.0.1
ibm/rational_doors_next_generation 6.0.2
ibm/rational_doors_next_generation 4.0.0 - 4.0.7
ibm/rational_engineering_lifecycle_manager 5.0.0
ibm/rational_engineering_lifecycle_manager 5.0.1
... and 34 more
Published Mar 20, 2018
Tracked Since Feb 18, 2026