Rational Collaborative Lifecycle Management
Vendor:
First CVE: Mar 2, 2014 · Active for 12 years
141
Total CVEs
More Total CVEs than 99% of tracked products
17.6
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 13% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Rational Collaborative Lifecycle Management over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 2, 2014
12 years ago
Most Recent CVE
Oct 27, 2021
1,734 days ago
CVE Severity & Scoring
Rational Collaborative Lifecycle Management141 CVEs
91%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local3 (2.1%)
Network128 (90.8%)
Unknown6 (4.3%)
Physical2 (1.4%)
Adjacent Network2 (1.4%)
Attack Complexity
Low131 (92.9%)
High4 (2.8%)
Unknown6 (4.3%)
User Interaction
None49 (34.8%)
Unknown6 (4.3%)
Required86 (61.0%)
Privileges Required
Low123 (87.2%)
High2 (1.4%)
None10 (7.1%)
Unknown6 (4.3%)
Top CVEs
Signals from CVEs in this product scope (141 CVEs).
141 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1701HIGH IBM Team Concert (RTC) 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, and 6.0.5 stores credentials for users using a weak encryption algorithm, which could allow an authentica | Apr 23, 2018 | 8.8 | 27 | NO | NO |
CVE-2014-0862HIGH Unspecified vulnerability in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x before 3.0.1.6 iFix 2 and 4.x before 4.0.6 allows remote attackers to exe | Mar 2, 2014 | 10.0 | 26 | NO | NO |
CVE-2021-29774HIGH IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025. | Oct 27, 2021 | 7.5 | 24 | NO | NO |
CVE-2019-4252HIGH IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted | Jun 27, 2019 | 7.5 | 24 | NO | NO |
CVE-2015-7440HIGH IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; | Mar 15, 2018 | 7.8 | 24 | NO | NO |
CVE-2016-2865MEDIUM The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecycle Management 5.x before 5.0.2 | Jul 15, 2016 | 6.5 | 23 | NO | NO |
CVE-2021-29786MEDIUM IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172. | Oct 27, 2021 | 6.5 | 22 | NO | NO |
CVE-2020-4974MEDIUM IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potential | Jul 28, 2021 | 6.3 | 22 | NO | NO |
CVE-2017-1700MEDIUM IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle | Apr 24, 2018 | 6.5 | 22 | NO | NO |
CVE-2016-2981MEDIUM An undisclosed vulnerability in the CLM applications in IBM Jazz Team Server may allow unauthorized access to user credentials. IBM Reference #: 1999965. | Mar 20, 2017 | 6.8 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (141 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (141 CVEs).
Media Mentions
Signals from CVEs in this product scope (141 CVEs).
Top CNAs Publishing CVEs For Rational Collaborative Lifecycle Management
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0.2 | 1 | 5.4 | 0.5% | 0 | 0 |
| 7.0.1 | 1 | 5.4 | 0.5% | 0 | 0 |
| 6.0.6.1 | 10 | 5.8 | 0.6% | 0 | 0 |
| 6.0.6 | 11 | 5.8 | 0.6% | 0 | 0 |
| 6.0.5 | 29 | 5.4 | 0.7% | 0 | 0 |
| 6.0.4 | 39 | 5.2 | 0.7% | 0 | 0 |
| 6.0.3 | 50 | 5.2 | 0.8% | 0 | 0 |
| 6.0.2 | 59 | 5.3 | 0.8% | 0 | 0 |
| 6.0.1 | 67 | 5.3 | 0.8% | 0 | 0 |
| 6.0.0 | 32 | 5.3 | 0.7% | 0 | 0 |
| 6.0 | 37 | 5.2 | 0.8% | 0 | 0 |
| 5.0.2 | 73 | 5.2 | 0.8% | 0 | 0 |
| 5.0.1 | 78 | 5.2 | 0.8% | 0 | 0 |
| 5.0.0 | 37 | 5.2 | 0.8% | 0 | 0 |
| 5.0 | 41 | 5.2 | 0.8% | 0 | 0 |
| 4.0.7 | 44 | 5.0 | 0.9% | 0 | 0 |
| 4.0.6 | 44 | 5.0 | 0.9% | 0 | 0 |
| 4.0.5 | 45 | 5.1 | 1.0% | 0 | 0 |
| 4.0.4 | 45 | 5.1 | 1.0% | 0 | 0 |
| 4.0.3 | 45 | 5.1 | 1.0% | 0 | 0 |