ZeroHour

CVE-2019-4252

CVSS 3.1
7.5 high
EPSS
3%p88
Published
()
Modified
Description

IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 159883.

Vendors
ibm
Products
rational collaborative lifecycle management, rational doors next generation, rational engineering lifecycle manager, rational quality manager, rational rhapsody design manager, rational software architect design manager, rational team concert
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.