CVE-2017-1602

MEDIUM

IBM Rational Collaborative Lifecycle Management 5.0-6.0 - Authenticated Unauthorized Access via Crafted URL

Title source: llm
STIX 2.1

Description

IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially crafted URL. IBM X-Force ID: 132625.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103477
Patch, Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg22014815
VDB Entry, Vendor Advisory x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/132625

Scores

CVSS v3 4.3
EPSS 0.0123
EPSS Percentile 64.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-552
Status published
Products (27)
ibm/rational_collaborative_lifecycle_management 4.0.0 - 6.0.5
ibm/rational_doors_next_generation 5.0.0
ibm/rational_doors_next_generation 5.0.1
ibm/rational_doors_next_generation 5.0.2
ibm/rational_doors_next_generation 4.0.1 - 4.0.7
ibm/rational_engineering_lifecycle_manager 5.0.0
ibm/rational_engineering_lifecycle_manager 5.0.1
ibm/rational_engineering_lifecycle_manager 5.0.2
ibm/rational_engineering_lifecycle_manager 4.0.3 - 4.0.7
ibm/rational_quality_manager 5.0.0
... and 17 more
Published Mar 23, 2018
Tracked Since Feb 18, 2026