CVE-2016-9748

MEDIUM

IBM Rational Doors Next Generation - Information Disclosure

Title source: rule

Description

IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system.

Scores

CVSS v3 4.3
EPSS 0.0018
EPSS Percentile 39.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-200
Status published

Affected Products (21)

ibm/rational_doors_next_generation
ibm/rational_doors_next_generation
ibm/rational_doors_next_generation
ibm/rational_doors_next_generation
ibm/rational_doors_next_generation
ibm/rational_doors_next_generation
ibm/rational_doors_next_generation
ibm/rational_requirements_composer
IBM Corporation/Rational DOORS Next Generation < 4.0.1
IBM Corporation/Rational DOORS Next Generation < 4.0.5
IBM Corporation/Rational DOORS Next Generation < 5.0.2
IBM Corporation/Rational DOORS Next Generation < 4.0.2
IBM Corporation/Rational DOORS Next Generation < 4.0.3
IBM Corporation/Rational DOORS Next Generation < 4.0.4
IBM Corporation/Rational DOORS Next Generation < 4.0.6
... and 6 more

Timeline

Published Feb 08, 2017
Tracked Since Feb 18, 2026