Rational Test Control Panel component stores MD5 hashes of user passwords, which has now proven to be insecure.
CVE ID: CVE-2015-1913
Description: Rational Test Control Panel generates and stores an MD5 hash of users’ passwords. The MD5 hash is persisted and used to authenticate the user the next time he/she logs into the server. The MD5 hash algorithm is understood to be vulnerable to an attack.
CVSS Base Score: 5 **CVSS Temporal Score:**See <https://exchange.xforce.ibmcloud.com/vulnerabilities/101855> for the current score *CVSS Environmental Score:**Undefined CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Rational Test Control Panel component in Rational Test Workbench and Rational Test Virtualization Server versions:
The fixes for the CVE(s) mentioned above have been incorporated into the latest fixpacks available from IBM.
Upgrade your installation as follows:
Visit IBM Fix Central to search for, download and apply the following fixpacks for your version of product:
None