CVE-2015-0121
Summary
| CVE | CVE-2015-0121 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-05-30 19:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next Generation (RDNG) 4.0 through 4.0.7 and 5.0 through 5.0.2, when LTPA single sign on is used with WebSphere Application Server, do not terminate a Requirements Management (RM) session upon LTPA token expiration, which allows remote attackers to obtain access by leveraging an unattended workstation. |
Risk And Classification
Primary CVSS: v2.0 3.7 from [email protected]
AV:L/AC:H/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:H/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Rational Doors Next Generation | 4.0.0 | All | All | All |
| Application | Ibm | Rational Doors Next Generation | 4.0.1 | All | All | All |
| Application | Ibm | Rational Doors Next Generation | 4.0.2 | All | All | All |
| Application | Ibm | Rational Doors Next Generation | 4.0.3 | All | All | All |
| Application | Ibm | Rational Doors Next Generation | 4.0.4 | All | All | All |
| Application | Ibm | Rational Doors Next Generation | 4.0.5 | All | All | All |
| Application | Ibm | Rational Doors Next Generation | 4.0.6 | All | All | All |
| Application | Ibm | Rational Doors Next Generation | 4.0.7 | All | All | All |
| Application | Ibm | Rational Doors Next Generation | 5.0 | All | All | All |
| Application | Ibm | Rational Doors Next Generation | 5.0.1 | All | All | All |
| Application | Ibm | Rational Doors Next Generation | 5.0.2 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 3.0 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 3.0.1 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 3.0.1.1 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 3.0.1.2 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 3.0.1.3 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 3.0.1.4 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 3.0.1.5 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 3.0.1.6 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 4.0 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 4.0.0 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 4.0.0.1 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 4.0.0.2 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 4.0.1 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 4.0.2 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 4.0.3 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 4.0.4 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 4.0.5 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 4.0.6 | All | All | All |
| Application | Ibm | Rational Requirements Composer | 4.0.7 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple IBM Products CVE-2015-0121 Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM Security Bulletin: Users are not logged out of the Requirements Management (RM) application after the LTPA timeout period is reached (CVE-2015-0121) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.