Rational Quality Manager

Vendor:

First CVE: Oct 26, 2010 · Active for 15 years

202
Total CVEs
More Total CVEs than 99% of tracked products
18.4
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Rational Quality Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2010
15 years ago
Most Recent CVE
Aug 29, 2022
1,427 days ago

CVE Severity & Scoring

Rational Quality Manager202 CVEs
All CVEs352,713 CVEs
LowMediumHigh
Attack Vector
Local3 (1.5%)
Network183 (90.6%)
Unknown13 (6.4%)
Physical1 (0.5%)
Adjacent Network2 (1.0%)
Attack Complexity
Low187 (92.6%)
High2 (1.0%)
Unknown13 (6.4%)
User Interaction
None55 (27.2%)
Unknown13 (6.4%)
Required134 (66.3%)
Privileges Required
Low176 (87.1%)
High3 (1.5%)
None10 (5.0%)
Unknown13 (6.4%)

Top CVEs

Signals from CVEs in this product scope (202 CVEs).

202 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier for remote attackers to execute
Oct 26, 20105.070NOYES
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted
Jun 27, 20197.524NONO
IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4;
Mar 15, 20187.824NONO
IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potential
Jul 28, 20216.322NONO
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information co
Jun 2, 20216.522NONO
IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126.
Jun 2, 20216.522NONO
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted re
Jun 2, 20218.822NONO
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle
Apr 24, 20186.522NONO
IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iFix17, and 6.x before 6.0.1 ifix
Oct 22, 20168.822NONO
IBM Jazz applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational DOORS Next Generation 5.0 through 5.02 and 6.0 through 6
Nov 6, 20185.921NONO

Exploit Exposure

Signals from CVEs in this product scope (202 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.5% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (202 CVEs).

Media Mentions

Signals from CVEs in this product scope (202 CVEs).

Top CNAs Publishing CVEs For Rational Quality Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.0.6.1455.50.7%00
6.0.6455.50.7%00
6.0.5295.40.7%00
6.0.4345.20.7%00
6.0.3465.30.8%00
6.0.2875.20.7%00
6.0.1625.30.8%00
6.0.0255.30.7%00
6.0375.40.8%00
5.0.2735.20.8%00
5.0.1815.10.8%00
5.0.0384.90.9%00
5.0445.20.8%00
4.0.7444.90.9%00
4.0.6375.00.9%00
4.0.5454.90.9%00
4.0.4464.80.9%00
4.0.3464.80.9%00
4.0.2464.80.9%00
4.0.1464.80.9%00