ID

VAR-201803-1089


CVE

CVE-2017-1524


TITLE

IBM Jazz Foundation Vulnerable to information disclosure

Trust: 0.8

sources: JVNDB: JVNDB-2018-003247

DESCRIPTION

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request that could be used to aid future attacks. IBM X-Force ID: 129970. Vendors have confirmed this vulnerability IBM X-Force ID: 129970 It is released as.Information may be obtained. Multiple IBM Products are prone to the following multiple security vulnerabilities: 1. An information-disclosure vulnerability 2. Multiple cross-site scripting vulnerability 3. An access-bypass vulnerability An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, gain unauthorized access to the affected application or to obtain sensitive information

Trust: 1.89

sources: NVD: CVE-2017-1524 // JVNDB: JVNDB-2018-003247 // BID: 103477

AFFECTED PRODUCTS

vendor:ibmmodel:rational team concertscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational team concertscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:6.0.1

Trust: 1.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational quality managerscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational quality managerscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational quality managerscope:eqversion:5.0.0

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:5.0.2

Trust: 1.3

vendor:ibmmodel:rational doors next generationscope:eqversion:5.0.1

Trust: 1.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0

Trust: 1.1

vendor:ibmmodel:rational engineering lifecycle managerscope:gteversion:4.0.3

Trust: 1.0

vendor:ibmmodel:rational software architect design managerscope:eqversion:5.0.0

Trust: 1.0

vendor:ibmmodel:rational doors next generationscope:gteversion:6.0.0

Trust: 1.0

vendor:ibmmodel:rational team concertscope:gteversion:4.0.0

Trust: 1.0

vendor:ibmmodel:rational engineering lifecycle managerscope:gteversion:6.0.0

Trust: 1.0

vendor:ibmmodel:rational doors next generationscope:eqversion:5.0.0

Trust: 1.0

vendor:ibmmodel:rational software architect design managerscope:lteversion:4.0.7

Trust: 1.0

vendor:ibmmodel:rational doors next generationscope:gteversion:4.0.1

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:lteversion:4.0.7

Trust: 1.0

vendor:ibmmodel:rational rhapsody design managerscope:gteversion:4.0

Trust: 1.0

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:5.0.0

Trust: 1.0

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:5.0.0

Trust: 1.0

vendor:ibmmodel:rational rhapsody design managerscope:gteversion:6.0.0

Trust: 1.0

vendor:ibmmodel:rational collaborative lifecycle managementscope:lteversion:6.0.5

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:lteversion:6.0.5

Trust: 1.0

vendor:ibmmodel:rational software architect design managerscope:eqversion:6.0.0

Trust: 1.0

vendor:ibmmodel:rational doors next generationscope:lteversion:4.0.7

Trust: 1.0

vendor:ibmmodel:rational team concertscope:gteversion:6.0.0

Trust: 1.0

vendor:ibmmodel:rational doors next generationscope:lteversion:6.0.5

Trust: 1.0

vendor:ibmmodel:rational software architect design managerscope:gteversion:4.0.0

Trust: 1.0

vendor:ibmmodel:rational engineering lifecycle managerscope:lteversion:4.0.7

Trust: 1.0

vendor:ibmmodel:rational team concertscope:eqversion:5.0.0

Trust: 1.0

vendor:ibmmodel:rational rhapsody design managerscope:lteversion:4.0.7

Trust: 1.0

vendor:ibmmodel:rational collaborative lifecycle managementscope:gteversion:4.0.0

Trust: 1.0

vendor:ibmmodel:rational engineering lifecycle managerscope:lteversion:6.0.5

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:gteversion:6.0

Trust: 1.0

vendor:ibmmodel:rational team concertscope:lteversion:4.0.7

Trust: 1.0

vendor:ibmmodel:rational rhapsody design managerscope:lteversion:6.0.5

Trust: 1.0

vendor:ibmmodel:rational quality managerscope:gteversion:4.0.0

Trust: 1.0

vendor:ibmmodel:rational team concertscope:lteversion:6.0.5

Trust: 1.0

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.4

Trust: 0.9

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.3

Trust: 0.9

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.2

Trust: 0.9

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.1

Trust: 0.9

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.6

Trust: 0.9

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.5

Trust: 0.9

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0

Trust: 0.9

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0.3

Trust: 0.9

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0.2

Trust: 0.9

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0.1

Trust: 0.9

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:5.0

Trust: 0.8

vendor:ibmmodel:rational doors next generationscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational engineering lifecycle managerscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational quality managerscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational rhapsody design managerscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational software architect design managerscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational team concertscope: - version: -

Trust: 0.8

vendor:ibmmodel:rational team concertscope:eqversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:6.0.3

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:6.0.1

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.5

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.4

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.3

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.2

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.1

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:6.0

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:5.0

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0.6

Trust: 0.3

vendor:ibmmodel:rational team concertscope:eqversion:4.0

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.3

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.2

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.1

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:6.0

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:5.0

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.6

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.5

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.4

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0.0

Trust: 0.3

vendor:ibmmodel:rational software architect design managerscope:eqversion:4.0

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0.3

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0.1

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:6.0

Trust: 0.3

vendor:ibmmodel:rational rhapsody design managerscope:eqversion:5.0

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:6.0.1

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.5

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.4

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.3

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.2

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.1

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:6.0.3

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:6.0

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:5.0

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0.6

Trust: 0.3

vendor:ibmmodel:rational quality managerscope:eqversion:4.0

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:4.0.5

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:4.0.4

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:4.0.3

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:6.0

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:5.0

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational engineering lifecycle managerscope:eqversion:4.0.6

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0.3

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0.1

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.5

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.4

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.3

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.2

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.1

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:6.0

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:5.0

Trust: 0.3

vendor:ibmmodel:rational doors next generationscope:eqversion:4.0.6

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0.4

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0.3

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0.1

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:5.0.7

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:5.0.2

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:5.0.1

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.7

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:5.0.0

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.6

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.5

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.4

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.3

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.2

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.1

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.0.2

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.0.1

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0.0

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle managementscope:eqversion:4.0

Trust: 0.3

vendor:ibmmodel:jazz team serverscope:eqversion:0

Trust: 0.3

vendor:ibmmodel:jazz foundationscope:eqversion:0

Trust: 0.3

vendor:ibmmodel:rational team concert ifix3scope:neversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational team concert ifix16scope:neversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational team concert ifix25scope:neversion:5.0.2

Trust: 0.3

vendor:ibmmodel:rational quality manager ifix3scope:neversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational quality manager ifix16scope:neversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational quality manager ifix25scope:neversion:5.0.2

Trust: 0.3

vendor:ibmmodel:rational doors next generation ifix3scope:neversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational doors next generation ifix16scope:neversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational doors next generation ifix25scope:neversion:5.0.2

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle management ifix3scope:neversion:6.0.5

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle management ifix16scope:neversion:6.0.2

Trust: 0.3

vendor:ibmmodel:rational collaborative lifecycle management ifix25scope:neversion:5.0.2

Trust: 0.3

sources: BID: 103477 // JVNDB: JVNDB-2018-003247 // CNNVD: CNNVD-201803-903 // NVD: CVE-2017-1524

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-1524
value: MEDIUM

Trust: 1.0

psirt@us.ibm.com: CVE-2017-1524
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-1524
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201803-903
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2017-1524
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2017-1524
baseSeverity: MEDIUM
baseScore: 4.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 1.4
version: 3.0

Trust: 2.8

sources: JVNDB: JVNDB-2018-003247 // CNNVD: CNNVD-201803-903 // NVD: CVE-2017-1524 // NVD: CVE-2017-1524

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.8

sources: JVNDB: JVNDB-2018-003247 // NVD: CVE-2017-1524

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201803-903

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201803-903

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-003247

PATCH

title:2014815url:http://www-01.ibm.com/support/docview.wss?uid=swg22014815

Trust: 0.8

title:ibm-jazz-cve20171524-info-disc (129970)url:https://exchange.xforce.ibmcloud.com/vulnerabilities/129970

Trust: 0.8

title:IBM Rational Collaborative Lifecycle Management Jazz Foundation Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=79400

Trust: 0.6

sources: JVNDB: JVNDB-2018-003247 // CNNVD: CNNVD-201803-903

EXTERNAL IDS

db:NVDid:CVE-2017-1524

Trust: 2.7

db:BIDid:103477

Trust: 1.9

db:JVNDBid:JVNDB-2018-003247

Trust: 0.8

db:CNNVDid:CNNVD-201803-903

Trust: 0.6

sources: BID: 103477 // JVNDB: JVNDB-2018-003247 // CNNVD: CNNVD-201803-903 // NVD: CVE-2017-1524

REFERENCES

url:http://www.ibm.com/support/docview.wss?uid=swg22014815

Trust: 1.6

url:http://www.securityfocus.com/bid/103477

Trust: 1.6

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/129970

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-1524

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-1524

Trust: 0.8

url:http://www.ibm.com

Trust: 0.3

url:http://www-01.ibm.com/support/docview.wss?uid=swg22014815

Trust: 0.3

sources: BID: 103477 // JVNDB: JVNDB-2018-003247 // CNNVD: CNNVD-201803-903 // NVD: CVE-2017-1524

CREDITS

IBM.

Trust: 0.3

sources: BID: 103477

SOURCES

db:BIDid:103477
db:JVNDBid:JVNDB-2018-003247
db:CNNVDid:CNNVD-201803-903
db:NVDid:CVE-2017-1524

LAST UPDATE DATE

2024-11-23T22:30:29.318000+00:00


SOURCES UPDATE DATE

db:BIDid:103477date:2018-03-20T00:00:00
db:JVNDBid:JVNDB-2018-003247date:2018-05-18T00:00:00
db:CNNVDid:CNNVD-201803-903date:2019-10-17T00:00:00
db:NVDid:CVE-2017-1524date:2024-11-21T03:22:01.087

SOURCES RELEASE DATE

db:BIDid:103477date:2018-03-20T00:00:00
db:JVNDBid:JVNDB-2018-003247date:2018-05-18T00:00:00
db:CNNVDid:CNNVD-201803-903date:2018-03-26T00:00:00
db:NVDid:CVE-2017-1524date:2018-03-23T19:29:00.230