Lucene search

K
cveIbmCVE-2014-3092
HistorySep 12, 2014 - 1:55 a.m.

CVE-2014-3092

2014-09-1201:55:06
CWE-200
ibm
web.nvd.nist.gov
27
ibm
jazz team server
rational collaborative lifecycle management
rational quality manager
security
vulnerability
session cookie
nvd
cve-2014-3092

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

54.9%

IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

Affected configurations

Nvd
Node
ibmrational_doors_next_generationMatch4.0.0
OR
ibmrational_doors_next_generationMatch4.0.1
OR
ibmrational_doors_next_generationMatch4.0.2
OR
ibmrational_doors_next_generationMatch4.0.3
OR
ibmrational_doors_next_generationMatch4.0.4
OR
ibmrational_doors_next_generationMatch4.0.5
OR
ibmrational_doors_next_generationMatch4.0.6
OR
ibmrational_doors_next_generationMatch5.0
OR
ibmrational_engineering_lifecycle_managerMatch1.0
OR
ibmrational_engineering_lifecycle_managerMatch1.0.0.1
OR
ibmrational_engineering_lifecycle_managerMatch4.03
OR
ibmrational_engineering_lifecycle_managerMatch4.04
OR
ibmrational_engineering_lifecycle_managerMatch4.05
OR
ibmrational_engineering_lifecycle_managerMatch4.06
OR
ibmrational_engineering_lifecycle_managerMatch5.0
OR
ibmrational_quality_managerMatch2.0
OR
ibmrational_quality_managerMatch2.0.0.1
OR
ibmrational_quality_managerMatch2.0.0.2
OR
ibmrational_quality_managerMatch2.0.1
OR
ibmrational_quality_managerMatch2.0.1.1
OR
ibmrational_quality_managerMatch3.0
OR
ibmrational_quality_managerMatch3.0.1
OR
ibmrational_quality_managerMatch3.0.1.1
OR
ibmrational_quality_managerMatch3.0.1.2
OR
ibmrational_quality_managerMatch3.0.1.3
OR
ibmrational_quality_managerMatch3.0.1.4
OR
ibmrational_quality_managerMatch3.0.1.5
OR
ibmrational_quality_managerMatch3.0.1.6
OR
ibmrational_quality_managerMatch4.0
OR
ibmrational_quality_managerMatch4.0.0.1
OR
ibmrational_quality_managerMatch4.0.0.2
OR
ibmrational_quality_managerMatch4.0.1
OR
ibmrational_quality_managerMatch4.0.2
OR
ibmrational_quality_managerMatch4.0.3
OR
ibmrational_quality_managerMatch4.0.4
OR
ibmrational_quality_managerMatch4.0.5
OR
ibmrational_quality_managerMatch4.0.6
OR
ibmrational_quality_managerMatch5.0
OR
ibmrational_requirements_composerMatch2.0
OR
ibmrational_requirements_composerMatch2.0.0.1
OR
ibmrational_requirements_composerMatch2.0.0.2
OR
ibmrational_requirements_composerMatch2.0.0.3
OR
ibmrational_requirements_composerMatch2.0.0.4
OR
ibmrational_requirements_composerMatch3.0
OR
ibmrational_requirements_composerMatch3.0.1
OR
ibmrational_requirements_composerMatch3.0.1.1
OR
ibmrational_requirements_composerMatch3.0.1.2
OR
ibmrational_requirements_composerMatch3.0.1.3
OR
ibmrational_requirements_composerMatch3.0.1.4
OR
ibmrational_requirements_composerMatch3.0.1.5
OR
ibmrational_requirements_composerMatch3.0.1.6
OR
ibmrational_requirements_composerMatch4.0
OR
ibmrational_requirements_composerMatch4.0.0
OR
ibmrational_requirements_composerMatch4.0.0.1
OR
ibmrational_requirements_composerMatch4.0.0.2
OR
ibmrational_requirements_composerMatch4.0.1
OR
ibmrational_requirements_composerMatch4.0.2
OR
ibmrational_requirements_composerMatch4.0.3
OR
ibmrational_requirements_composerMatch4.0.4
OR
ibmrational_requirements_composerMatch4.0.5
OR
ibmrational_requirements_composerMatch4.0.6
OR
ibmrational_rhapsody_design_managerMatch3.0
OR
ibmrational_rhapsody_design_managerMatch3.0.0.1
OR
ibmrational_rhapsody_design_managerMatch3.0.1
OR
ibmrational_rhapsody_design_managerMatch4.0
OR
ibmrational_rhapsody_design_managerMatch4.0.1
OR
ibmrational_rhapsody_design_managerMatch4.0.2
OR
ibmrational_rhapsody_design_managerMatch4.0.3
OR
ibmrational_rhapsody_design_managerMatch4.0.4
OR
ibmrational_rhapsody_design_managerMatch4.0.5
OR
ibmrational_rhapsody_design_managerMatch4.0.6
OR
ibmrational_rhapsody_design_managerMatch5.0
OR
ibmrational_software_architect_design_managerMatch3.0
OR
ibmrational_software_architect_design_managerMatch3.0.0
OR
ibmrational_software_architect_design_managerMatch3.0.0.1
OR
ibmrational_software_architect_design_managerMatch3.0.1
OR
ibmrational_software_architect_design_managerMatch4.0.0
OR
ibmrational_software_architect_design_managerMatch4.0.1
OR
ibmrational_software_architect_design_managerMatch4.0.2
OR
ibmrational_software_architect_design_managerMatch4.0.3
OR
ibmrational_software_architect_design_managerMatch4.0.4
OR
ibmrational_software_architect_design_managerMatch4.0.5
OR
ibmrational_software_architect_design_managerMatch4.0.6
OR
ibmrational_software_architect_design_managerMatch5.0
OR
ibmrational_team_concertMatch2.0
OR
ibmrational_team_concertMatch2.0.0.1
OR
ibmrational_team_concertMatch2.0.0.2
OR
ibmrational_team_concertMatch3.0
OR
ibmrational_team_concertMatch3.0.1
OR
ibmrational_team_concertMatch3.0.1.1
OR
ibmrational_team_concertMatch3.0.1.2
OR
ibmrational_team_concertMatch3.0.1.3
OR
ibmrational_team_concertMatch3.0.1.4
OR
ibmrational_team_concertMatch3.0.1.5
OR
ibmrational_team_concertMatch3.0.1.6
OR
ibmrational_team_concertMatch4.0
OR
ibmrational_team_concertMatch4.0.0.1
OR
ibmrational_team_concertMatch4.0.0.2
OR
ibmrational_team_concertMatch4.0.1
OR
ibmrational_team_concertMatch4.0.2
OR
ibmrational_team_concertMatch4.0.3
OR
ibmrational_team_concertMatch4.0.4
OR
ibmrational_team_concertMatch4.0.5
OR
ibmrational_team_concertMatch4.0.6
OR
ibmrational_team_concertMatch5.0
VendorProductVersionCPE
ibmrational_doors_next_generation4.0.0cpe:2.3:a:ibm:rational_doors_next_generation:4.0.0:*:*:*:*:*:*:*
ibmrational_doors_next_generation4.0.1cpe:2.3:a:ibm:rational_doors_next_generation:4.0.1:*:*:*:*:*:*:*
ibmrational_doors_next_generation4.0.2cpe:2.3:a:ibm:rational_doors_next_generation:4.0.2:*:*:*:*:*:*:*
ibmrational_doors_next_generation4.0.3cpe:2.3:a:ibm:rational_doors_next_generation:4.0.3:*:*:*:*:*:*:*
ibmrational_doors_next_generation4.0.4cpe:2.3:a:ibm:rational_doors_next_generation:4.0.4:*:*:*:*:*:*:*
ibmrational_doors_next_generation4.0.5cpe:2.3:a:ibm:rational_doors_next_generation:4.0.5:*:*:*:*:*:*:*
ibmrational_doors_next_generation4.0.6cpe:2.3:a:ibm:rational_doors_next_generation:4.0.6:*:*:*:*:*:*:*
ibmrational_doors_next_generation5.0cpe:2.3:a:ibm:rational_doors_next_generation:5.0:*:*:*:*:*:*:*
ibmrational_engineering_lifecycle_manager1.0cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:1.0:*:*:*:*:*:*:*
ibmrational_engineering_lifecycle_manager1.0.0.1cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:1.0.0.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 1051

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

54.9%

Related for CVE-2014-3092