Rational Quality Manager
Vendor:
First CVE: Oct 26, 2010 · Active for 15 years
202
Total CVEs
More Total CVEs than 99% of tracked products
18.4
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Rational Quality Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2010
15 years ago
Most Recent CVE
Aug 29, 2022
1,427 days ago
CVE Severity & Scoring
Rational Quality Manager202 CVEs
91%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local3 (1.5%)
Network183 (90.6%)
Unknown13 (6.4%)
Physical1 (0.5%)
Adjacent Network2 (1.0%)
Attack Complexity
Low187 (92.6%)
High2 (1.0%)
Unknown13 (6.4%)
User Interaction
None55 (27.2%)
Unknown13 (6.4%)
Required134 (66.3%)
Privileges Required
Low176 (87.1%)
High3 (1.5%)
None10 (5.0%)
Unknown13 (6.4%)
Top CVEs
Signals from CVEs in this product scope (202 CVEs).
202 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4094MEDIUM The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier for remote attackers to execute | Oct 26, 2010 | 5.0 | 70 | NO | YES |
CVE-2019-4252HIGH IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted | Jun 27, 2019 | 7.5 | 24 | NO | NO |
CVE-2015-7440HIGH IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; | Mar 15, 2018 | 7.8 | 24 | NO | NO |
CVE-2020-4974MEDIUM IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potential | Jul 28, 2021 | 6.3 | 22 | NO | NO |
CVE-2021-20371MEDIUM IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information co | Jun 2, 2021 | 6.5 | 22 | NO | NO |
CVE-2020-4732MEDIUM IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126. | Jun 2, 2021 | 6.5 | 22 | NO | NO |
CVE-2020-4495HIGH IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted re | Jun 2, 2021 | 8.8 | 22 | NO | NO |
CVE-2017-1700MEDIUM IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle | Apr 24, 2018 | 6.5 | 22 | NO | NO |
CVE-2016-0326HIGH IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iFix17, and 6.x before 6.0.1 ifix | Oct 22, 2016 | 8.8 | 22 | NO | NO |
CVE-2018-1694MEDIUM IBM Jazz applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational DOORS Next Generation 5.0 through 5.02 and 6.0 through 6 | Nov 6, 2018 | 5.9 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (202 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.5% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (202 CVEs).
Media Mentions
Signals from CVEs in this product scope (202 CVEs).
Top CNAs Publishing CVEs For Rational Quality Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.0.6.1 | 45 | 5.5 | 0.7% | 0 | 0 |
| 6.0.6 | 45 | 5.5 | 0.7% | 0 | 0 |
| 6.0.5 | 29 | 5.4 | 0.7% | 0 | 0 |
| 6.0.4 | 34 | 5.2 | 0.7% | 0 | 0 |
| 6.0.3 | 46 | 5.3 | 0.8% | 0 | 0 |
| 6.0.2 | 87 | 5.2 | 0.7% | 0 | 0 |
| 6.0.1 | 62 | 5.3 | 0.8% | 0 | 0 |
| 6.0.0 | 25 | 5.3 | 0.7% | 0 | 0 |
| 6.0 | 37 | 5.4 | 0.8% | 0 | 0 |
| 5.0.2 | 73 | 5.2 | 0.8% | 0 | 0 |
| 5.0.1 | 81 | 5.1 | 0.8% | 0 | 0 |
| 5.0.0 | 38 | 4.9 | 0.9% | 0 | 0 |
| 5.0 | 44 | 5.2 | 0.8% | 0 | 0 |
| 4.0.7 | 44 | 4.9 | 0.9% | 0 | 0 |
| 4.0.6 | 37 | 5.0 | 0.9% | 0 | 0 |
| 4.0.5 | 45 | 4.9 | 0.9% | 0 | 0 |
| 4.0.4 | 46 | 4.8 | 0.9% | 0 | 0 |
| 4.0.3 | 46 | 4.8 | 0.9% | 0 | 0 |
| 4.0.2 | 46 | 4.8 | 0.9% | 0 | 0 |
| 4.0.1 | 46 | 4.8 | 0.9% | 0 | 0 |