Vulnerabilities > CVE-2014-0844 - Information Disclosure vulnerability in IBM products

047910
CVSS 3.5 - LOW
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
ibm

Summary

Unspecified vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users to read arbitrary data via unknown vectors.

Seebug

bulletinFamilyexploit
descriptionCVE ID:CVE-2014-0844、CVE-2014-0845、CVE-2014-0846 IBM Rational Requirements Composer软件是一项需求定义解决方案,旨在通过为需求信息提供共享位置,并帮助进行反复改进以实现平衡解决方案。IBM Rational DOORS是一款需求管理工具,它通过改进需求沟通与协作,可以最大限度地提高业务流程。 IBM Rational Requirements Composer和IBM Rational DOORS存在多个安全漏洞: 1,存在未明安全漏洞,允许远程攻击者利用漏洞未授权获取应用程序或系统数据(CVE-2014-0844)。 2,存在未明重定向漏洞,允许远程攻击者构建恶意URI,诱使用户解析,可对用户进行网络钓鱼等攻击(CVE-2014-0845)。 3,存在未明安全漏洞,允许远程攻击者构建恶意URI,诱使用户解析,对用户进行跨站脚本攻击(CVE-2014-0846)。 0 IBM Rational Requirements Composer 2.x IBM Rational Requirements Composer 3.x IBM Rational Requirements Composer 4.x IBM Rational DOORS Next Generation 4.x 厂商补丁: IBM ----- 用户可参考如下厂商提供的安全公告获取补丁以修复该漏洞: http://www-01.ibm.com/support/docview.wss?uid=swg21664412
idSSV:61652
last seen2017-11-19
modified2014-03-05
published2014-03-05
reporterRoot
titleIBM Rational多个产品多个安全漏洞