CVE-2016-2865Sensitive Information Exposure in IBM Rational Collaborative Lifecycle Management

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 57.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateMay 17

Description

The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecycle Management 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 allows remote authenticated users to obtain sensitive information via a malformed request.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2gc2-4gm5-9ghf: The GIT Integration component in IBM Rational Team Concert (RTC) 52022-05-17
CVEList
CVE-2016-2865: The GIT Integration component in IBM Rational Team Concert (RTC) 52016-07-15
CVE-2016-2865 — Sensitive Information Exposure in IBM | cvebase