Rational Engineering Lifecycle Manager
Vendor:
First CVE: Sep 10, 2014 · Active for 11 years
141
Total CVEs
More Total CVEs than 99% of tracked products
17.6
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Rational Engineering Lifecycle Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 10, 2014
11 years ago
Most Recent CVE
Oct 27, 2021
1,731 days ago
CVE Severity & Scoring
Rational Engineering Lifecycle Manager141 CVEs
88%
9%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local3 (2.1%)
Network131 (92.9%)
Unknown4 (2.8%)
Physical1 (0.7%)
Adjacent Network2 (1.4%)
Attack Complexity
Low134 (95.0%)
High3 (2.1%)
Unknown4 (2.8%)
User Interaction
None61 (43.3%)
Unknown4 (2.8%)
Required76 (53.9%)
Privileges Required
Low125 (88.7%)
High2 (1.4%)
None10 (7.1%)
Unknown4 (2.8%)
Top CVEs
Signals from CVEs in this product scope (141 CVEs).
141 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-29844HIGH IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potential | Oct 27, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-29774HIGH IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025. | Oct 27, 2021 | 7.5 | 24 | NO | NO |
CVE-2019-4252HIGH IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted | Jun 27, 2019 | 7.5 | 24 | NO | NO |
CVE-2018-1608HIGH IBM Rational Engineering Lifecycle Manager 6.0 through 6.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information | May 1, 2019 | 7.5 | 24 | NO | NO |
CVE-2018-1846HIGH IBM Rational Engineering Lifecycle Manager 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote | Nov 2, 2018 | 7.1 | 24 | NO | NO |
CVE-2018-1607HIGH IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote a | Sep 25, 2018 | 7.1 | 24 | NO | NO |
CVE-2015-7440HIGH IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; | Mar 15, 2018 | 7.8 | 24 | NO | NO |
CVE-2021-20502HIGH IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose | Mar 30, 2021 | 7.1 | 23 | NO | NO |
CVE-2021-29786MEDIUM IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172. | Oct 27, 2021 | 6.5 | 22 | NO | NO |
CVE-2020-4974MEDIUM IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potential | Jul 28, 2021 | 6.3 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (141 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (141 CVEs).
Media Mentions
Signals from CVEs in this product scope (141 CVEs).
Top CNAs Publishing CVEs For Rational Engineering Lifecycle Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0.2 | 5 | 6.5 | 0.6% | 0 | 0 |
| 7.0.1 | 5 | 6.5 | 0.6% | 0 | 0 |
| 7.0 | 10 | 6.1 | 0.6% | 0 | 0 |
| 6.0.6.1 | 42 | 5.6 | 0.7% | 0 | 0 |
| 6.0.6 | 42 | 5.6 | 0.7% | 0 | 0 |
| 6.0.4 | 12 | 4.9 | 0.8% | 0 | 0 |
| 6.0.3 | 18 | 5.1 | 0.9% | 0 | 0 |
| 6.0.2 | 50 | 5.2 | 0.8% | 0 | 0 |
| 6.0.1 | 32 | 5.1 | 0.9% | 0 | 0 |
| 6.0.0 | 19 | 4.9 | 0.7% | 0 | 0 |
| 6.0 | 13 | 5.3 | 1.0% | 0 | 0 |
| 5.0.2 | 40 | 5.0 | 0.9% | 0 | 0 |
| 5.0.1 | 44 | 4.9 | 0.9% | 0 | 0 |
| 5.0.0 | 21 | 4.9 | 0.8% | 0 | 0 |
| 5.0 | 22 | 5.1 | 1.0% | 0 | 0 |
| 4.0.7 | 34 | 4.9 | 0.9% | 0 | 0 |
| 4.0.6 | 34 | 4.9 | 0.9% | 0 | 0 |
| 4.06 | 1 | 5.0 | 1.7% | 0 | 0 |
| 4.0.5 | 34 | 4.9 | 0.9% | 0 | 0 |
| 4.05 | 2 | 5.5 | 1.2% | 0 | 0 |