Vulnerability Name: CVE-2015-1971 Assigned: 2015-02-19 Published: 2016-01-02 Updated: 2016-01-07 Summary: Unspecified vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF8, and 5.x before 5.0.2 IF10; Rational Team Concert (RTC) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF8, and 5.x before 5.0.2 IF10; Rational Requirements Composer (RRC) 2.x and 3.x before 3.0.1.6 IF7 and 4.0 through 4.0.7; Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Engineering Lifecycle Manager (RELM) 1.0 through 1.0.0.1, 4.0.3 through 4.0.7, and 5.0 through 5.0.2; Rational Rhapsody Design Manager (DM) 3.0 through 3.0.1, 4.0 through 4.0.7, 5.0 through 5.0.2, and 6.0; and Rational Software Architect Design Manager (DM) 3.0 through 3.0.1, 4.0 through 4.0.7, and 5.0 through 5.0.2 allows remote attackers to cause a denial of service via unknown vectors. CVSS v3 Severity: 4.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L )Exploitability Metrics: Attack Vector (AV): AdjacentAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Low
4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L )Exploitability Metrics: Attack Vector (AV): AdjacentAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Low
CVSS v2 Severity: 3.3 Low (CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P )Exploitability Metrics: Access Vector (AV): Adjacent_NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
3.3 Low (CCN CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P )Exploitability Metrics: Access Vector (AV): Adjacent_NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
Vulnerability Type: CWE-noinfo References: Source: MITRE Type: CNACVE-2015-1971 Source: CONFIRM Type: Vendor Advisoryhttp://www-01.ibm.com/support/docview.wss?uid=swg21971164 Vulnerable Configuration: Configuration 1 :cpe:/a:ibm:rational_quality_manager:2.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:2.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:3.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:3.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:3.0.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:3.0.1.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:3.0.1.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:3.0.1.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:3.0.1.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:3.0.1.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:4.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:5.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_quality_manager:5.0.2:*:*:*:*:*:*:* Configuration 2 :cpe:/a:ibm:rational_engineering_lifecycle_manager:1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:1.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:4.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:4.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:4.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:4.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:4.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:5.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_engineering_lifecycle_manager:5.0.2:*:*:*:*:*:*:* Configuration 3 :cpe:/a:ibm:rational_team_concert:2.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:2.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:2.0.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:3.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:3.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:3.0.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:3.0.1.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:3.0.1.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:3.0.1.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:3.0.1.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:3.0.1.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:4.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:5.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_team_concert:5.0.2:*:*:*:*:*:*:* Configuration 4 :cpe:/a:ibm:rational_software_architect_design_manager:3.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:3.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:3.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:4.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:4.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:4.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:4.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:4.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:4.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:4.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:4.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:5.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_software_architect_design_manager:5.0.2:*:*:*:*:*:*:* Configuration 5 :cpe:/a:ibm:rational_doors_next_generation:4.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:4.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:4.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:4.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:4.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:4.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:4.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:4.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:5.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_doors_next_generation:5.0.2:*:*:*:*:*:*:* Configuration 6 :cpe:/a:ibm:rational_requirements_composer:2.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:2.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:2.0.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:2.0.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:2.0.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:3.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:3.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:3.0.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:3.0.1.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:3.0.1.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:3.0.1.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:3.0.1.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:3.0.1.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:4.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:4.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:4.0.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:4.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:4.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:4.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:4.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:4.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:4.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_requirements_composer:4.0.7:*:*:*:*:*:*:* Configuration 7 :cpe:/a:ibm:rational_rhapsody_design_manager:3.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:3.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:3.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:4.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:4.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:4.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:4.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:4.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:4.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:4.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:4.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:5.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:5.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_rhapsody_design_manager:6.0:*:*:*:*:*:*:* Configuration 8 :cpe:/a:ibm:rational_collaborative_lifecycle_management:3.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:4.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:5.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_collaborative_lifecycle_management:5.0.2:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
ibm rational quality manager 2.0
ibm rational quality manager 2.0.1
ibm rational quality manager 3.0
ibm rational quality manager 3.0.1
ibm rational quality manager 3.0.1.1
ibm rational quality manager 3.0.1.2
ibm rational quality manager 3.0.1.3
ibm rational quality manager 3.0.1.4
ibm rational quality manager 3.0.1.5
ibm rational quality manager 3.0.1.6
ibm rational quality manager 4.0
ibm rational quality manager 4.0.0.1
ibm rational quality manager 4.0.0.2
ibm rational quality manager 4.0.1
ibm rational quality manager 4.0.2
ibm rational quality manager 4.0.3
ibm rational quality manager 4.0.4
ibm rational quality manager 4.0.5
ibm rational quality manager 4.0.6
ibm rational quality manager 4.0.7
ibm rational quality manager 5.0
ibm rational quality manager 5.0.1
ibm rational quality manager 5.0.2
ibm rational engineering lifecycle manager 1.0
ibm rational engineering lifecycle manager 1.0.0.1
ibm rational engineering lifecycle manager 4.0.3
ibm rational engineering lifecycle manager 4.0.4
ibm rational engineering lifecycle manager 4.0.5
ibm rational engineering lifecycle manager 4.0.6
ibm rational engineering lifecycle manager 4.0.7
ibm rational engineering lifecycle manager 5.0
ibm rational engineering lifecycle manager 5.0.1
ibm rational engineering lifecycle manager 5.0.2
ibm rational team concert 2.0
ibm rational team concert 2.0.0.1
ibm rational team concert 2.0.0.2
ibm rational team concert 3.0
ibm rational team concert 3.0.1
ibm rational team concert 3.0.1.1
ibm rational team concert 3.0.1.2
ibm rational team concert 3.0.1.3
ibm rational team concert 3.0.1.4
ibm rational team concert 3.0.1.5
ibm rational team concert 3.0.1.6
ibm rational team concert 4.0
ibm rational team concert 4.0.0.1
ibm rational team concert 4.0.0.2
ibm rational team concert 4.0.1
ibm rational team concert 4.0.2
ibm rational team concert 4.0.3
ibm rational team concert 4.0.4
ibm rational team concert 4.0.5
ibm rational team concert 4.0.6
ibm rational team concert 4.0.7
ibm rational team concert 5.0
ibm rational team concert 5.0.1
ibm rational team concert 5.0.2
ibm rational software architect design manager 3.0
ibm rational software architect design manager 3.0.0.1
ibm rational software architect design manager 3.0.1
ibm rational software architect design manager 4.0
ibm rational software architect design manager 4.0.1
ibm rational software architect design manager 4.0.2
ibm rational software architect design manager 4.0.3
ibm rational software architect design manager 4.0.4
ibm rational software architect design manager 4.0.5
ibm rational software architect design manager 4.0.6
ibm rational software architect design manager 4.0.7
ibm rational software architect design manager 5.0
ibm rational software architect design manager 5.0.1
ibm rational software architect design manager 5.0.2
ibm rational doors next generation 4.0
ibm rational doors next generation 4.0.1
ibm rational doors next generation 4.0.2
ibm rational doors next generation 4.0.3
ibm rational doors next generation 4.0.4
ibm rational doors next generation 4.0.5
ibm rational doors next generation 4.0.6
ibm rational doors next generation 4.0.7
ibm rational doors next generation 5.0
ibm rational doors next generation 5.0.1
ibm rational doors next generation 5.0.2
ibm rational requirements composer 2.0
ibm rational requirements composer 2.0.0.1
ibm rational requirements composer 2.0.0.2
ibm rational requirements composer 2.0.0.3
ibm rational requirements composer 2.0.0.4
ibm rational requirements composer 3.0
ibm rational requirements composer 3.0.1
ibm rational requirements composer 3.0.1.1
ibm rational requirements composer 3.0.1.2
ibm rational requirements composer 3.0.1.3
ibm rational requirements composer 3.0.1.4
ibm rational requirements composer 3.0.1.5
ibm rational requirements composer 3.0.1.6
ibm rational requirements composer 4.0
ibm rational requirements composer 4.0.0.1
ibm rational requirements composer 4.0.0.2
ibm rational requirements composer 4.0.1
ibm rational requirements composer 4.0.2
ibm rational requirements composer 4.0.3
ibm rational requirements composer 4.0.4
ibm rational requirements composer 4.0.5
ibm rational requirements composer 4.0.6
ibm rational requirements composer 4.0.7
ibm rational rhapsody design manager 3.0
ibm rational rhapsody design manager 3.0.0.1
ibm rational rhapsody design manager 3.0.1
ibm rational rhapsody design manager 4.0
ibm rational rhapsody design manager 4.0.1
ibm rational rhapsody design manager 4.0.2
ibm rational rhapsody design manager 4.0.3
ibm rational rhapsody design manager 4.0.4
ibm rational rhapsody design manager 4.0.5
ibm rational rhapsody design manager 4.0.6
ibm rational rhapsody design manager 4.0.7
ibm rational rhapsody design manager 5.0
ibm rational rhapsody design manager 5.0.1
ibm rational rhapsody design manager 5.0.2
ibm rational rhapsody design manager 6.0
ibm rational collaborative lifecycle management 3.0.1
ibm rational collaborative lifecycle management 4.0.1
ibm rational collaborative lifecycle management 4.0.2
ibm rational collaborative lifecycle management 4.0.3
ibm rational collaborative lifecycle management 4.0.4
ibm rational collaborative lifecycle management 4.0.5
ibm rational collaborative lifecycle management 4.0.6
ibm rational collaborative lifecycle management 4.0.7
ibm rational collaborative lifecycle management 5.0
ibm rational collaborative lifecycle management 5.0.1
ibm rational collaborative lifecycle management 5.0.2