3.7
CVSSv2

CVE-2015-0121

Published: 30/05/2015 Updated: 03/12/2016
CVSS v2 Base Score: 3.7 | Impact Score: 6.4 | Exploitability Score: 1.9
VMScore: 329
Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

IBM Rational Requirements Composer 3.0 up to and including 3.0.1.6 and 4.0 up to and including 4.0.7 and Rational DOORS Next Generation (RDNG) 4.0 up to and including 4.0.7 and 5.0 up to and including 5.0.2, when LTPA single sign on is used with WebSphere Application Server, do not terminate a Requirements Management (RM) session upon LTPA token expiration, which allows remote malicious users to obtain access by leveraging an unattended workstation.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm rational requirements composer 3.0

ibm rational requirements composer 3.0.1

ibm rational requirements composer 3.0.1.1

ibm rational requirements composer 3.0.1.2

ibm rational requirements composer 4.0.0.1

ibm rational requirements composer 4.0.0.2

ibm rational requirements composer 4.0.1

ibm rational requirements composer 3.0.1.5

ibm rational requirements composer 3.0.1.6

ibm rational requirements composer 4.0.4

ibm rational requirements composer 4.0.5

ibm rational requirements composer 4.0

ibm rational requirements composer 4.0.0

ibm rational requirements composer 4.0.6

ibm rational requirements composer 4.0.7

ibm rational requirements composer 3.0.1.3

ibm rational requirements composer 3.0.1.4

ibm rational requirements composer 4.0.2

ibm rational requirements composer 4.0.3

ibm rational doors next generation 4.0.0

ibm rational doors next generation 4.0.7

ibm rational doors next generation 5.0

ibm rational doors next generation 4.0.3

ibm rational doors next generation 4.0.4

ibm rational doors next generation 4.0.5

ibm rational doors next generation 4.0.6

ibm rational doors next generation 4.0.1

ibm rational doors next generation 4.0.2

ibm rational doors next generation 5.0.1

ibm rational doors next generation 5.0.2