Vulnerability Description
IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Manager (RQM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Team Concert (RTC) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Requirements Composer (RRC) 4.0.x before 4.0.7 iFix10; Rational DOORS Next Generation (RDNG) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Engineering Lifecycle Manager (RELM) 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7 before iFix1, 5.0.x before 5.0.2 iFix1, and 6.0.x before 6.0.2; Rational Rhapsody Design Manager (Rhapsody DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Software Architect Design Manager (RSA DM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2 allow local users to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 108221.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Rational Collaborative Lifecycle Management | >= 4.0.0, <= 6.0.2 |
| Ibm | Rational Quality Manager | >= 4.0.0, <= 4.0.7 |
| Ibm | Rational Team Concert | >= 4.0.0, <= 4.0.7 |
| Ibm | Rational Requirements Composer | >= 4.0.0, <= 4.0.7 |
| Ibm | Rational Doors Next Generation | >= 4.0.0, <= 4.0.7 |
| Ibm | Rational Engineering Lifecycle Manager | >= 4.0.3, <= 4.0.7 |
| Ibm | Rational Rhapsody Design Manager | >= 4.0, <= 4.0.7 |
| Ibm | Rational Software Architect Design Manager | >= 4.0.0, <= 4.0.7 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21985143PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/108221VDB EntryVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21985143PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/108221VDB EntryVendor Advisory
FAQ
What is CVE-2015-7449?
CVE-2015-7449 is a vulnerability with a CVSS score of 3.3 (LOW). IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Manager (RQM) 4.0.x befor...
How severe is CVE-2015-7449?
CVE-2015-7449 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7449?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Rational Collaborative Lifecycle Management, Ibm Rational Quality Manager, Ibm Rational Team Concert, Ibm Rational Requirements Composer, Ibm Rational Doors Next Generation.