Rational Engineering Lifecycle Manager

Vendor:

First CVE: Sep 10, 2014 · Active for 11 years

141
Total CVEs
More Total CVEs than 99% of tracked products
17.6
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Rational Engineering Lifecycle Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 10, 2014
11 years ago
Most Recent CVE
Oct 27, 2021
1,731 days ago

CVE Severity & Scoring

Rational Engineering Lifecycle Manager141 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local3 (2.1%)
Network131 (92.9%)
Unknown4 (2.8%)
Physical1 (0.7%)
Adjacent Network2 (1.4%)
Attack Complexity
Low134 (95.0%)
High3 (2.1%)
Unknown4 (2.8%)
User Interaction
None61 (43.3%)
Unknown4 (2.8%)
Required76 (53.9%)
Privileges Required
Low125 (88.7%)
High2 (1.4%)
None10 (7.1%)
Unknown4 (2.8%)

Top CVEs

Signals from CVEs in this product scope (141 CVEs).

141 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potential
Oct 27, 20218.826NONO
IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.
Oct 27, 20217.524NONO
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted
Jun 27, 20197.524NONO
IBM Rational Engineering Lifecycle Manager 6.0 through 6.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
May 1, 20197.524NONO
IBM Rational Engineering Lifecycle Manager 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote
Nov 2, 20187.124NONO
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote a
Sep 25, 20187.124NONO
IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4;
Mar 15, 20187.824NONO
IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose
Mar 30, 20217.123NONO
IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.
Oct 27, 20216.522NONO
IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potential
Jul 28, 20216.322NONO

Exploit Exposure

Signals from CVEs in this product scope (141 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (141 CVEs).

Media Mentions

Signals from CVEs in this product scope (141 CVEs).

Top CNAs Publishing CVEs For Rational Engineering Lifecycle Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.0.256.50.6%00
7.0.156.50.6%00
7.0106.10.6%00
6.0.6.1425.60.7%00
6.0.6425.60.7%00
6.0.4124.90.8%00
6.0.3185.10.9%00
6.0.2505.20.8%00
6.0.1325.10.9%00
6.0.0194.90.7%00
6.0135.31.0%00
5.0.2405.00.9%00
5.0.1444.90.9%00
5.0.0214.90.8%00
5.0225.11.0%00
4.0.7344.90.9%00
4.0.6344.90.9%00
4.0615.01.7%00
4.0.5344.90.9%00
4.0525.51.2%00