Rational Collaborative Lifecycle Management

Vendor:

First CVE: Mar 2, 2014 · Active for 12 years

141
Total CVEs
More Total CVEs than 99% of tracked products
17.6
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 13% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Rational Collaborative Lifecycle Management over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 2, 2014
12 years ago
Most Recent CVE
Oct 27, 2021
1,734 days ago

CVE Severity & Scoring

Rational Collaborative Lifecycle Management141 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local3 (2.1%)
Network128 (90.8%)
Unknown6 (4.3%)
Physical2 (1.4%)
Adjacent Network2 (1.4%)
Attack Complexity
Low131 (92.9%)
High4 (2.8%)
Unknown6 (4.3%)
User Interaction
None49 (34.8%)
Unknown6 (4.3%)
Required86 (61.0%)
Privileges Required
Low123 (87.2%)
High2 (1.4%)
None10 (7.1%)
Unknown6 (4.3%)

Top CVEs

Signals from CVEs in this product scope (141 CVEs).

141 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Team Concert (RTC) 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, and 6.0.5 stores credentials for users using a weak encryption algorithm, which could allow an authentica
Apr 23, 20188.827NONO
Unspecified vulnerability in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x before 3.0.1.6 iFix 2 and 4.x before 4.0.6 allows remote attackers to exe
Mar 2, 201410.026NONO
IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.
Oct 27, 20217.524NONO
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted
Jun 27, 20197.524NONO
IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4;
Mar 15, 20187.824NONO
The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecycle Management 5.x before 5.0.2
Jul 15, 20166.523NONO
IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.
Oct 27, 20216.522NONO
IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potential
Jul 28, 20216.322NONO
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle
Apr 24, 20186.522NONO
An undisclosed vulnerability in the CLM applications in IBM Jazz Team Server may allow unauthorized access to user credentials. IBM Reference #: 1999965.
Mar 20, 20176.822NONO

Exploit Exposure

Signals from CVEs in this product scope (141 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (141 CVEs).

Media Mentions

Signals from CVEs in this product scope (141 CVEs).

Top CNAs Publishing CVEs For Rational Collaborative Lifecycle Management

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.0.215.40.5%00
7.0.115.40.5%00
6.0.6.1105.80.6%00
6.0.6115.80.6%00
6.0.5295.40.7%00
6.0.4395.20.7%00
6.0.3505.20.8%00
6.0.2595.30.8%00
6.0.1675.30.8%00
6.0.0325.30.7%00
6.0375.20.8%00
5.0.2735.20.8%00
5.0.1785.20.8%00
5.0.0375.20.8%00
5.0415.20.8%00
4.0.7445.00.9%00
4.0.6445.00.9%00
4.0.5455.11.0%00
4.0.4455.11.0%00
4.0.3455.11.0%00