ID

VAR-201711-0485


CVE

CVE-2017-1570


TITLE

IBM Jazz Foundation Vulnerable to information disclosure

Trust: 0.8

sources: JVNDB: JVNDB-2017-010847

DESCRIPTION

IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 131852. Vendors have confirmed this vulnerability IBM X-Force ID: 131852 It is released as.Information may be obtained. Attackers can exploit this issue to obtain sensitive information that may aid in further attacks. IBM Jazz Team Server affects the following IBM Rational products: Collaborative Lifecycle Management (CLM) Rational DOORS Next Generation (RDNG) Rational Engineering Lifecycle Manager (RELM) Rational Team Concert (RTC) Rational Quality Manager (RQM) Rational Rhapsody Design Manager (Rhapsody DM) Rational Software Architect (RSA DM)

Trust: 1.89

sources: NVD: CVE-2017-1570 // JVNDB: JVNDB-2017-010847 // BID: 102020

AFFECTED PRODUCTS

vendor:ibmmodel:rational team concertscope:eqversion:4.0.3

Trust: 1.9

vendor:ibmmodel:rational team concertscope:eqversion:4.0.2

Trust: 1.9

vendor:ibmmodel:rational team concertscope:eqversion:4.0.1

Trust: 1.9

vendor:ibmmodel:rational team concertscope:eqversion:4.0.0.2

Trust: 1.9

vendor:ibmmodel:rational team concertscope:eqversion:4.0.0.1

Trust: 1.9

vendor:ibmmodel:rational quality managerscope:eqversion:6.0.1

Trust: 1.6

vendor:ibmmodel:rational quality managerscope:eqversion:6.0.2

Trust: 1.6

vendor:ibmmodel:rational quality managerscope:eqversion:6.0

Trust: 1.6

vendor:ibmmodel:rational quality managerscope:eqversion:6.0.4

Trust: 1.6

vendor:ibmmodel:rational quality managerscope:eqversion:6.0.3

Trust: 1.6

vendor:ibmmodel:rational team concertscope:eqversion:6.0.4

Trust: 1.3

vendor:ibmmodel:rational team concertscope:eqversion:6.0.3

Trust: 1.3

vendor:ibmmodel:rational team concertscope:eqversion:6.0.2

Trust: 1.3

vendor:ibmmodel:rational team concertscope:eqversion:6.0.1

Trust: 1.3

vendor:ibmmodel:rational team concertscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.5

Trust: 1.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.4

Trust: 1.3

vendor:ibmmodel:rational team concertscope:eqversion:6.0

Trust: 1.3

vendor:ibmmodel:rational team concertscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational team concertscope:eqversion:5.0

Trust: 1.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.7

Trust: 1.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.6

Trust: 1.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0

Trust: 1.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:6.0.1

Trust: 1.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.7

Trust: 1.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.3

Trust: 1.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.2

Trust: 1.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.1

Trust: 1.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:6.0

Trust: 1.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:5.0

Trust: 1.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.6

Trust: 1.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.5

Trust: 1.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.4

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0.4

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0.3

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0.2

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0.1

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.7

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.4

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.3

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.2

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.1

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:5.0

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.6

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.5

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0.3

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0.2

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0.1

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:4.0.5

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:4.0.4

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:4.0.3

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0.4

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:5.0

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:4.0.7

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:4.0.6

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0.4

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0.3

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0.2

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0.1

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.7

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.5

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.4

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.3

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.2

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.1

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:5.0

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.6

Trust: 1.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0.4

Trust: 1.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0.3

Trust: 1.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0.1

Trust: 1.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.7

Trust: 1.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0

Trust: 1.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.6

Trust: 1.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.5

Trust: 1.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.4

Trust: 1.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.3

Trust: 1.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.2

Trust: 1.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.1

Trust: 1.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.5

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.0.2

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.3

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:eqversion:5.0.1

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.4

Trust: 1.0

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0

Trust: 1.0

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.1

Trust: 1.0

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:5.0

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.0.1

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.7

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.6

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:eqversion:5.0.2

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.2

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:eqversion:4.0

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:eqversion:5.0

Trust: 1.0

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0

Trust: 1.0

vendor:ibmmodel:rational collaborative lifecycle managementscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational doors next generationscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational engineering lifecycle managerscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational quality managerscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational rhapsody design managerscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational software architect design managerscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational team concertscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational software architect design managerscope:eqversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:6.0.3

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.0

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.0

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.0

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:5.0.7

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:5.0.0

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.0.2

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.0.1

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.0

Trust: 0.3

vendor:ibmmodel:jazz team serverscope:eqversion:0

Trust: 0.3

vendor:ibmmodel:rational team concert ifix5scope:neversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational team concert ifix14scope:neversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational team concert ifix24scope:neversion:5.0.2

Trust: 0.3

vendor:ibmmodel:rational team concert ifix15scope:neversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational software architect design manager ifix5scope:neversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational software architect design manager ifix14scope:neversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational software architect design manager ifix24scope:neversion:5.0.2

Trust: 0.3

vendor:ibmmodel:rational software architect design manager ifix15scope:neversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational rhapsody design manager ifix5scope:neversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational rhapsody design manager ifix14scope:neversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational rhapsody design manager ifix24scope:neversion:5.0.2

Trust: 0.3

vendor:ibmmodel:rational rhapsody design manager ifix15scope:neversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle manager ifix5scope:neversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle manager ifix14scope:neversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle manager ifix24scope:neversion:5.0.2

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle manager ifix15scope:neversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational doors next generation ifix5scope:neversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational doors next generation ifix14scope:neversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational doors next generation ifix24scope:neversion:5.0.2

Trust: 0.3

vendor:ibmmodel:rational doors next generation ifix15scope:neversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle management ifix5scope:neversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle management ifix14scope:neversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle management ifix24scope:neversion:5.0.2

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle management ifix15scope:neversion:4.0.7

Trust: 0.3

sources: BID: 102020 // JVNDB: JVNDB-2017-010847 // CNNVD: CNNVD-201711-1083 // NVD: CVE-2017-1570

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-1570
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-1570
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201711-1083
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2017-1570
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2017-1570
baseSeverity: MEDIUM
baseScore: 4.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 1.4
version: 3.0

Trust: 1.8

sources: JVNDB: JVNDB-2017-010847 // CNNVD: CNNVD-201711-1083 // NVD: CVE-2017-1570

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.8

sources: JVNDB: JVNDB-2017-010847 // NVD: CVE-2017-1570

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201711-1083

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201711-1083

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-010847

PATCH

title:2010512url:http://www-01.ibm.com/support/docview.wss?uid=swg22010512

Trust: 0.8

title:IBM Rational Collaborative Lifecycle Management Repair measures for information disclosure vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=76757

Trust: 0.6

sources: JVNDB: JVNDB-2017-010847 // CNNVD: CNNVD-201711-1083

EXTERNAL IDS

db:NVDid:CVE-2017-1570

Trust: 2.7

db:BIDid:102020

Trust: 1.3

db:JVNDBid:JVNDB-2017-010847

Trust: 0.8

db:CNNVDid:CNNVD-201711-1083

Trust: 0.6

sources: BID: 102020 // JVNDB: JVNDB-2017-010847 // CNNVD: CNNVD-201711-1083 // NVD: CVE-2017-1570

REFERENCES

url:http://www.ibm.com/support/docview.wss?uid=swg22010512

Trust: 1.6

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/131852

Trust: 1.6

url:http://www.securityfocus.com/bid/102020

Trust: 1.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-1570

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-1570

Trust: 0.8

url:http://www.ibm.com/

Trust: 0.3

url:http://www-01.ibm.com/support/docview.wss?uid=swg22010512

Trust: 0.3

sources: BID: 102020 // JVNDB: JVNDB-2017-010847 // CNNVD: CNNVD-201711-1083 // NVD: CVE-2017-1570

CREDITS

The vendor reported the issue.

Trust: 0.3

sources: BID: 102020

SOURCES

db:BIDid:102020
db:JVNDBid:JVNDB-2017-010847
db:CNNVDid:CNNVD-201711-1083
db:NVDid:CVE-2017-1570

LAST UPDATE DATE

2024-11-23T22:52:19.674000+00:00


SOURCES UPDATE DATE

db:BIDid:102020date:2017-12-19T22:37:00
db:JVNDBid:JVNDB-2017-010847date:2017-12-26T00:00:00
db:CNNVDid:CNNVD-201711-1083date:2017-11-28T00:00:00
db:NVDid:CVE-2017-1570date:2024-11-21T03:22:06.143

SOURCES RELEASE DATE

db:BIDid:102020date:2017-11-15T00:00:00
db:JVNDBid:JVNDB-2017-010847date:2017-12-26T00:00:00
db:CNNVDid:CNNVD-201711-1083date:2017-11-28T00:00:00
db:NVDid:CVE-2017-1570date:2017-11-27T21:29:00.503