Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-0121

Опубликовано: 30 мая 2015
Источник: nvd
CVSS2: 3.7
EPSS Низкий

Описание

IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next Generation (RDNG) 4.0 through 4.0.7 and 5.0 through 5.0.2, when LTPA single sign on is used with WebSphere Application Server, do not terminate a Requirements Management (RM) session upon LTPA token expiration, which allows remote attackers to obtain access by leveraging an unattended workstation.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:rational_requirements_composer:3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:3.0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:3.0.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:3.0.1.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:3.0.1.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:3.0.1.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:3.0.1.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:4.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:4.0.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:4.0.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_requirements_composer:4.0.7:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:ibm:rational_doors_next_generation:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_doors_next_generation:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_doors_next_generation:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_doors_next_generation:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_doors_next_generation:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_doors_next_generation:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_doors_next_generation:4.0.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_doors_next_generation:4.0.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_doors_next_generation:5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_doors_next_generation:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_doors_next_generation:5.0.2:*:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.00193
Низкий

3.7 Low

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next Generation (RDNG) 4.0 through 4.0.7 and 5.0 through 5.0.2, when LTPA single sign on is used with WebSphere Application Server, do not terminate a Requirements Management (RM) session upon LTPA token expiration, which allows remote attackers to obtain access by leveraging an unattended workstation.

EPSS

Процентиль: 41%
0.00193
Низкий

3.7 Low

CVSS2

Дефекты

NVD-CWE-Other