CVE-2011-1389
Summary
| CVE | CVE-2011-1389 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-01-19 19:55:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple directory traversal vulnerabilities in the vendor daemon in Rational Common Licensing in Telelogic License Server 2.0, Rational License Server 7.x, and ibmratl in IBM Rational License Key Server (RLKS) 8.0 through 8.1.2 allow remote attackers to execute arbitrary code via vectors related to save, rename, and load operations on log files. NOTE: this might overlap CVE-2011-4135. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Rational License Key Server | 8.0 | All | All | All |
| Application | Ibm | Rational License Key Server | 8.1 | All | All | All |
| Application | Ibm | Rational License Key Server | 8.1.1 | All | All | All |
| Application | Ibm | Rational License Key Server | 8.1.2 | All | All | All |
| Application | Ibm | Rational License Server | 7.0 | All | All | All |
| Application | Ibm | Rational License Server | 7.1 | All | All | All |
| Application | Ibm | Rational License Server | 7.5 | All | All | All |
| Application | Ibm | Telelogic License Server | 2.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| Security Bulletin: Vulnerability in Rational License Key Server affecting both the license server, lmgrd, and the vendor daemon, ibmratl (CVE-2011-1389) | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Patch, Vendor Advisory |
| FlexNet License Server Manager Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IT Management Software, Optimization & Solutions | Flexera | af854a3a-2127-422b-91ae-364da2661108 | www.flexerasoftware.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Security Advisory SA47524 - IBM Telelogic / Rational License Server License Manager Log File Upload Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Customer Community | af854a3a-2127-422b-91ae-364da2661108 | kb.flexerasoftware.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.