ID

VAR-201803-0148


CVE

CVE-2017-1602


TITLE

IBM RSA DM Access control vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-003248

DESCRIPTION

IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially crafted URL. IBM X-Force ID: 132625. Vendors have confirmed this vulnerability IBM X-Force ID: 132625 It is released as.Information may be tampered with. Multiple IBM Products are prone to the following multiple security vulnerabilities: 1. An information-disclosure vulnerability 2. Multiple cross-site scripting vulnerability 3. An access-bypass vulnerability An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, gain unauthorized access to the affected application or to obtain sensitive information

Trust: 1.89

sources: NVD: CVE-2017-1602 // JVNDB: JVNDB-2018-003248 // BID: 103477

AFFECTED PRODUCTS

vendor:ibmmodel:rational software architect design managerscope:eqversion:6.0.1

Trust: 1.9

vendor:ibmmodel:rational software architect design managerscope:eqversion:5.0.2

Trust: 1.9

vendor:ibmmodel:rational software architect design managerscope:eqversion:5.0.1

Trust: 1.9

vendor:ibmmodel:rational software architect design managerscope:eqversion:6.0.0

Trust: 1.6

vendor:ibmmodel:rational software architect design managerscope:eqversion:5.0.0

Trust: 1.6

vendor:ibmmodel:rational team concertscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational team concertscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational quality managerscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational quality managerscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational quality managerscope:eqversion:5.0.0

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0

Trust: 1.1

vendor:ibmmodel:rational engineering lifecycle managerscope:gteversion:4.0.3

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:gteversion:6.0.0

Trust: 1.0

vendor:ibmmodel:rational doors next generationscope:gteversion:6.0.0

Trust: 1.0

vendor:ibmmodel:rational team concertscope:gteversion:4.0.0

Trust: 1.0

vendor:ibmmodel:rational engineering lifecycle managerscope:gteversion:6.0.0

Trust: 1.0

vendor:ibmmodel:rational doors next generationscope:eqversion:5.0.0

Trust: 1.0

vendor:ibmmodel:rational software architect design managerscope:lteversion:4.0.7

Trust: 1.0

vendor:ibmmodel:rational doors next generationscope:gteversion:4.0.1

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:lteversion:4.0.7

Trust: 1.0

vendor:ibmmodel:rational rhapsody design managerscope:gteversion:4.0

Trust: 1.0

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:5.0.0

Trust: 1.0

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:5.0.0

Trust: 1.0

vendor:ibmmodel:rational rhapsody design managerscope:gteversion:6.0.0

Trust: 1.0

vendor:ibmmodel:rational collaborative lifecycle managementscope:lteversion:6.0.5

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:lteversion:6.0.5

Trust: 1.0

vendor:ibmmodel:rational doors next generationscope:lteversion:4.0.7

Trust: 1.0

vendor:ibmmodel:rational team concertscope:gteversion:6.0.0

Trust: 1.0

vendor:ibmmodel:rational doors next generationscope:lteversion:6.0.5

Trust: 1.0

vendor:ibmmodel:rational software architect design managerscope:gteversion:4.0.0

Trust: 1.0

vendor:ibmmodel:rational engineering lifecycle managerscope:lteversion:4.0.7

Trust: 1.0

vendor:ibmmodel:rational team concertscope:eqversion:5.0.0

Trust: 1.0

vendor:ibmmodel:rational rhapsody design managerscope:lteversion:4.0.7

Trust: 1.0

vendor:ibmmodel:rational collaborative lifecycle managementscope:gteversion:4.0.0

Trust: 1.0

vendor:ibmmodel:rational engineering lifecycle managerscope:lteversion:6.0.5

Trust: 1.0

vendor:ibmmodel:rational team concertscope:lteversion:4.0.7

Trust: 1.0

vendor:ibmmodel:rational rhapsody design managerscope:lteversion:6.0.5

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:gteversion:4.0.0

Trust: 1.0

vendor:ibmmodel:rational team concertscope:lteversion:6.0.5

Trust: 1.0

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.7

Trust: 0.9

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.3

Trust: 0.9

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.6

Trust: 0.9

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.5

Trust: 0.9

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.4

Trust: 0.9

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:5.0

Trust: 0.8

vendor:ibmmodel:rational doors next generationscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational engineering lifecycle managerscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational quality managerscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational rhapsody design managerscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational software architect design managerscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational team concertscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational team concertscope:eqversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:6.0.3

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:6.0.1

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.5

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.4

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.3

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.2

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.1

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:6.0

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:5.0

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.6

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.2

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.1

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:6.0

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:5.0

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.0

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0.3

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0.1

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.4

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.3

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.2

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.1

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:5.0

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.6

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.5

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:6.0.1

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.5

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.4

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.3

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.2

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.1

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:6.0.3

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:6.0

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:5.0

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.6

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0.3

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0.1

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:4.0.5

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:4.0.4

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:4.0.3

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:5.0

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:4.0.6

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0.3

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0.1

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.5

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.4

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.3

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.2

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.1

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:5.0

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.6

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0.3

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0.1

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:5.0.7

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:5.0.2

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:5.0.1

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:5.0.0

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.6

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.5

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.4

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.3

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.2

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.1

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.0.2

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.0.1

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.0

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0

Trust: 0.3

vendor:ibmmodel:jazz team serverscope:eqversion:0

Trust: 0.3

vendor:ibmmodel:jazz foundationscope:eqversion:0

Trust: 0.3

vendor:ibmmodel:rational team concert ifix3scope:neversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational team concert ifix16scope:neversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational team concert ifix25scope:neversion:5.0.2

Trust: 0.3

vendor:ibmmodel:rational quality manager ifix3scope:neversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational quality manager ifix16scope:neversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational quality manager ifix25scope:neversion:5.0.2

Trust: 0.3

vendor:ibmmodel:rational doors next generation ifix3scope:neversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational doors next generation ifix16scope:neversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational doors next generation ifix25scope:neversion:5.0.2

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle management ifix3scope:neversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle management ifix16scope:neversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle management ifix25scope:neversion:5.0.2

Trust: 0.3

sources: BID: 103477 // JVNDB: JVNDB-2018-003248 // CNNVD: CNNVD-201803-902 // NVD: CVE-2017-1602

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-1602
value: MEDIUM

Trust: 1.0

psirt@us.ibm.com: CVE-2017-1602
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-1602
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201803-902
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2017-1602
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2017-1602
baseSeverity: MEDIUM
baseScore: 4.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 1.4
version: 3.0

Trust: 2.8

sources: JVNDB: JVNDB-2018-003248 // CNNVD: CNNVD-201803-902 // NVD: CVE-2017-1602 // NVD: CVE-2017-1602

PROBLEMTYPE DATA

problemtype:CWE-552

Trust: 1.0

problemtype:CWE-284

Trust: 0.8

sources: JVNDB: JVNDB-2018-003248 // NVD: CVE-2017-1602

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201803-902

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201803-902

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-003248

PATCH

title:2014815url:http://www-01.ibm.com/support/docview.wss?uid=swg22014815

Trust: 0.8

title:ibm-rsadm-cve20171602-sec-bypass (132625)url:https://exchange.xforce.ibmcloud.com/vulnerabilities/132625

Trust: 0.8

title:IBM Rational Collaborative Lifecycle Management RSA DM Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=79399

Trust: 0.6

sources: JVNDB: JVNDB-2018-003248 // CNNVD: CNNVD-201803-902

EXTERNAL IDS

db:NVDid:CVE-2017-1602

Trust: 2.7

db:BIDid:103477

Trust: 1.9

db:JVNDBid:JVNDB-2018-003248

Trust: 0.8

db:CNNVDid:CNNVD-201803-902

Trust: 0.6

sources: BID: 103477 // JVNDB: JVNDB-2018-003248 // CNNVD: CNNVD-201803-902 // NVD: CVE-2017-1602

REFERENCES

url:http://www.ibm.com/support/docview.wss?uid=swg22014815

Trust: 1.6

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/132625

Trust: 1.6

url:http://www.securityfocus.com/bid/103477

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-1602

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-1602

Trust: 0.8

url:http://www.ibm.com

Trust: 0.3

url:http://www-01.ibm.com/support/docview.wss?uid=swg22014815

Trust: 0.3

sources: BID: 103477 // JVNDB: JVNDB-2018-003248 // CNNVD: CNNVD-201803-902 // NVD: CVE-2017-1602

CREDITS

IBM.

Trust: 0.3

sources: BID: 103477

SOURCES

db:BIDid:103477
db:JVNDBid:JVNDB-2018-003248
db:CNNVDid:CNNVD-201803-902
db:NVDid:CVE-2017-1602

LAST UPDATE DATE

2024-11-23T22:30:29.402000+00:00


SOURCES UPDATE DATE

db:BIDid:103477date:2018-03-20T00:00:00
db:JVNDBid:JVNDB-2018-003248date:2018-05-18T00:00:00
db:CNNVDid:CNNVD-201803-902date:2019-10-17T00:00:00
db:NVDid:CVE-2017-1602date:2024-11-21T03:22:07.950

SOURCES RELEASE DATE

db:BIDid:103477date:2018-03-20T00:00:00
db:JVNDBid:JVNDB-2018-003248date:2018-05-18T00:00:00
db:CNNVDid:CNNVD-201803-902date:2018-03-26T00:00:00
db:NVDid:CVE-2017-1602date:2018-03-23T19:29:00.277