CVE-2016-2865
Summary
| CVE | CVE-2016-2865 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-07-15 18:59:07 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecycle Management 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 allows remote authenticated users to obtain sensitive information via a malformed request. |
Risk And Classification
Primary CVSS: v3.0 6.5 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Problem Types: CWE-200 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 6.5 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| 2.0 | [email protected] | Primary | 4 | AV:N/AC:L/Au:S/C:P/I:N/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Rational Collaborative Lifecycle Management | 5.0.0 | All | All | All |
| Application | Ibm | Rational Collaborative Lifecycle Management | 5.0.1 | All | All | All |
| Application | Ibm | Rational Collaborative Lifecycle Management | 5.0.2 | All | All | All |
| Application | Ibm | Rational Collaborative Lifecycle Management | 6.0.0 | All | All | All |
| Application | Ibm | Rational Collaborative Lifecycle Management | 6.0.1 | All | All | All |
| Application | Ibm | Rational Team Concert | 5.0.0 | All | All | All |
| Application | Ibm | Rational Team Concert | 5.0.1 | All | All | All |
| Application | Ibm | Rational Team Concert | 5.0.2 | All | All | All |
| Application | Ibm | Rational Team Concert | 6.0.0 | All | All | All |
| Application | Ibm | Rational Team Concert | 6.0.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Rational Team Concert CVE-2016-2865 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Security Bulletin: Vulnerability affects IBM® Rational Team Concert™ GIT Integration (CVE-2016-2865 ) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.