CVE-2018-1587
published 2018-07-19CVE-2018-1587: IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0…
PriorityP420medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
0.98%
58.2th percentile
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 could reveal technical error messages to allow an adversary to gain information about the application and database that could be used to conduct further attacks. IBM X-Force ID: 143500.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | — | — |
| ibm | rational_rhapsody_design_manager | 5.0 – 5.0.2 | — |
| ibm | rational_rhapsody_design_manager | 6.0 – 6.0.5 | — |
| ibm | rational_software_architect_design_manager | — | — |
| ibm | rational_software_architect_design_manager | — | — |
| ibm | rational_software_architect_design_manager | — | — |
| ibm | rational_software_architect_design_manager | — | — |
| ibm | rational_software_architect_design_manager | — | — |
| ibm | rational_software_architect_design_manager | 5.0 – 5.0.2 | — |
| ibm | rational_software_architect_design_manager | 6.0 – 6.0.1 | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-07-19
Published