Lucene search

K
cveIbmCVE-2016-2981
HistoryMar 20, 2017 - 4:59 p.m.

CVE-2016-2981

2017-03-2016:59:01
CWE-200
ibm
web.nvd.nist.gov
26
cve-2016-2981
ibm
jazz team server
clm
vulnerability
unauthorized access
user credentials
nvd
1999965

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

36.9%

An undisclosed vulnerability in the CLM applications in IBM Jazz Team Server may allow unauthorized access to user credentials. IBM Reference #: 1999965.

Affected configurations

Nvd
Vulners
Node
ibmrational_collaborative_lifecycle_managementMatch4.0
OR
ibmrational_collaborative_lifecycle_managementMatch4.0.1
OR
ibmrational_collaborative_lifecycle_managementMatch4.0.2
OR
ibmrational_collaborative_lifecycle_managementMatch4.0.3
OR
ibmrational_collaborative_lifecycle_managementMatch4.0.4
OR
ibmrational_collaborative_lifecycle_managementMatch4.0.5
OR
ibmrational_collaborative_lifecycle_managementMatch4.0.6
OR
ibmrational_collaborative_lifecycle_managementMatch4.0.7
OR
ibmrational_collaborative_lifecycle_managementMatch5.0
OR
ibmrational_collaborative_lifecycle_managementMatch5.0.1
OR
ibmrational_collaborative_lifecycle_managementMatch5.0.2
OR
ibmrational_collaborative_lifecycle_managementMatch6.0
OR
ibmrational_collaborative_lifecycle_managementMatch6.0.1
OR
ibmrational_collaborative_lifecycle_managementMatch6.0.2
OR
ibmrational_collaborative_lifecycle_managementMatch6.0.3
VendorProductVersionCPE
ibmrational_collaborative_lifecycle_management4.0cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0:*:*:*:*:*:*:*
ibmrational_collaborative_lifecycle_management4.0.1cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.1:*:*:*:*:*:*:*
ibmrational_collaborative_lifecycle_management4.0.2cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.2:*:*:*:*:*:*:*
ibmrational_collaborative_lifecycle_management4.0.3cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.3:*:*:*:*:*:*:*
ibmrational_collaborative_lifecycle_management4.0.4cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.4:*:*:*:*:*:*:*
ibmrational_collaborative_lifecycle_management4.0.5cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.5:*:*:*:*:*:*:*
ibmrational_collaborative_lifecycle_management4.0.6cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.6:*:*:*:*:*:*:*
ibmrational_collaborative_lifecycle_management4.0.7cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.7:*:*:*:*:*:*:*
ibmrational_collaborative_lifecycle_management5.0cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0:*:*:*:*:*:*:*
ibmrational_collaborative_lifecycle_management5.0.1cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 151

CNA Affected

[
  {
    "product": "Rational Collaborative Lifecycle Management",
    "vendor": "IBM Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "3.0.1"
      },
      {
        "status": "affected",
        "version": "4.0"
      },
      {
        "status": "affected",
        "version": "3.0.1.6"
      },
      {
        "status": "affected",
        "version": "4.0.1"
      },
      {
        "status": "affected",
        "version": "4.0.2"
      },
      {
        "status": "affected",
        "version": "4.0.3"
      },
      {
        "status": "affected",
        "version": "4.0.4"
      },
      {
        "status": "affected",
        "version": "4.0.5"
      },
      {
        "status": "affected",
        "version": "4.0.6"
      },
      {
        "status": "affected",
        "version": "5.0"
      },
      {
        "status": "affected",
        "version": "4.0.7"
      },
      {
        "status": "affected",
        "version": "5.0.1"
      },
      {
        "status": "affected",
        "version": "5.0.2"
      },
      {
        "status": "affected",
        "version": "6.0"
      },
      {
        "status": "affected",
        "version": "6.0.1"
      },
      {
        "status": "affected",
        "version": "6.0.2"
      },
      {
        "status": "affected",
        "version": "6.0.3"
      }
    ]
  }
]

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

36.9%

Related for CVE-2016-2981