[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-0121Date: (C)2015-06-03   (M)2023-12-22


IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next Generation (RDNG) 4.0 through 4.0.7 and 5.0 through 5.0.2, when LTPA single sign on is used with WebSphere Application Server, do not terminate a Requirements Management (RM) session upon LTPA token expiration, which allows remote attackers to obtain access by leveraging an unattended workstation.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.7
Exploit Score: 1.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: HIGH
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
BID-74910
http://www-01.ibm.com/support/docview.wss?uid=swg21903761

CPE    30
cpe:/a:ibm:rational_doors_next_generation:5.0
cpe:/a:ibm:rational_requirements_composer:4.0.0.1
cpe:/a:ibm:rational_requirements_composer:4.0.0.2
cpe:/a:ibm:rational_doors_next_generation:4.0.0
...

© SecPod Technologies