CVE-2019-4084

MEDIUM

IBM Jazz Foundation <6.0.6.1 - Info Disclosure

Title source: llm

Description

IBM Jazz Foundation products (IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1) could allow an authenticated user to obtain sensitive information from CLM Applications that could be used in further attacks against the system. IBM X-Force ID: 157384.

Scores

CVSS v3 4.3
EPSS 0.0016
EPSS Percentile 36.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

Status published

Affected Products (7)

ibm/rational_collaborative_lifecycle_management < 6.0.6.1
ibm/rational_doors_next_generation < 6.0.6.1
ibm/rational_engineering_lifecycle_manager < 6.0.6.1
ibm/rational_quality_manager < 6.0.6.1
ibm/rational_rhapsody_design_manager < 6.0.6.1
ibm/rational_software_architect_design_manager < 6.0.1
ibm/rational_team_concert < 6.0.6.1

Timeline

Published Jun 27, 2019
Tracked Since Feb 18, 2026