4.3
CVSSv2

CVE-2016-0372

Published: 24/11/2016 Updated: 28/11/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 3.7 | Impact Score: 1.4 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 prior to 4.0.7 iFix11, 5.0 prior to 5.0.2 iFix18, and 6.0 prior to 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 prior to 4.0.7 iFix11, 5.0 prior to 5.0.2 iFix18, and 6.0 prior to 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 prior to 4.0.7 iFix11, 5.0 prior to 5.0.2 iFix18, and 6.0 prior to 6.0.2 iFix5; Rational DOORS Next Generation 4.0 prior to 4.0.7 iFix11, 5.0 prior to 5.0.2 iFix18, and 6.0 prior to 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x prior to 4.0.7 iFix11, 5.0 prior to 5.0.2 iFix18, and 6.0 prior to 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 prior to 4.0.7 iFix11, 5.0 prior to 5.0.2 iFix18, and 6.0 prior to 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 prior to 4.0.7 iFix11, 5.0 prior to 5.0.2 iFix18, and 6.0 prior to 6.0.2 iFix5 do not set the secure flag for the session cookie in an https session, which makes it easier for remote malicious users to capture this cookie by intercepting its transmission within an http session.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm rational team concert 4.0.5

ibm rational team concert 4.0.6

ibm rational team concert 4.0.1

ibm rational team concert 4.0.2

ibm rational team concert 5.0.2

ibm rational team concert 6.0.0

ibm rational team concert 3.0.1.6

ibm rational team concert 4.0.0

ibm rational team concert 4.0.7

ibm rational team concert 5.0.0

ibm rational team concert 5.0.1

ibm rational team concert 4.0.3

ibm rational team concert 4.0.4

ibm rational team concert 6.0.1

ibm rational team concert 6.0.2

ibm rational quality manager 3.0.1.6

ibm rational quality manager 4.0.6

ibm rational quality manager 4.0.7

ibm rational quality manager 4.0.2

ibm rational quality manager 4.0.3

ibm rational quality manager 5.0.2

ibm rational quality manager 6.0.0

ibm rational quality manager 4.0.0

ibm rational quality manager 4.0.1

ibm rational quality manager 5.0.0

ibm rational quality manager 5.0.1

ibm rational quality manager 4.0.4

ibm rational quality manager 4.0.5

ibm rational quality manager 6.0.1

ibm rational quality manager 6.0.2

ibm rational software architect design manager 4.0.0

ibm rational software architect design manager 5.0.0

ibm rational software architect design manager 5.0.1

ibm rational software architect design manager 4.0.4

ibm rational software architect design manager 4.0.5

ibm rational software architect design manager 6.0.1

ibm rational software architect design manager 6.0.2

ibm rational software architect design manager 4.0.2

ibm rational software architect design manager 4.0.1

ibm rational software architect design manager 4.0.3

ibm rational software architect design manager 5.0.2

ibm rational software architect design manager 6.0.0

ibm rational software architect design manager 4.0.6

ibm rational software architect design manager 4.0.7

ibm rational collaborative lifecycle management 6.0.2

ibm rational collaborative lifecycle management 6.0.0

ibm rational collaborative lifecycle management 4.0.3

ibm rational collaborative lifecycle management 4.0.4

ibm rational collaborative lifecycle management 4.0.5

ibm rational collaborative lifecycle management 5.0.2

ibm rational collaborative lifecycle management 4.0.0

ibm rational collaborative lifecycle management 3.0.1.6

ibm rational collaborative lifecycle management 5.0.0

ibm rational collaborative lifecycle management 5.0.1

ibm rational collaborative lifecycle management 4.0.6

ibm rational collaborative lifecycle management 4.0.7

ibm rational collaborative lifecycle management 6.0.1

ibm rational collaborative lifecycle management 4.0.1

ibm rational collaborative lifecycle management 4.0.2

ibm rational engineering lifecycle manager 4.0.2

ibm rational engineering lifecycle manager 4.0.3

ibm rational engineering lifecycle manager 5.0.2

ibm rational engineering lifecycle manager 6.0.0

ibm rational engineering lifecycle manager 4.0.6

ibm rational engineering lifecycle manager 4.0.7

ibm rational engineering lifecycle manager 4.0.4

ibm rational engineering lifecycle manager 4.0.5

ibm rational engineering lifecycle manager 6.0.1

ibm rational engineering lifecycle manager 6.0.2

ibm rational engineering lifecycle manager 4.0.0

ibm rational engineering lifecycle manager 4.0.1

ibm rational engineering lifecycle manager 5.0.0

ibm rational engineering lifecycle manager 5.0.1

ibm rational rhapsody design manager 4.0.4

ibm rational rhapsody design manager 4.0.5

ibm rational rhapsody design manager 6.0.1

ibm rational rhapsody design manager 6.0.2

ibm rational rhapsody design manager 4.0

ibm rational rhapsody design manager 5.0.0

ibm rational rhapsody design manager 5.0.1

ibm rational rhapsody design manager 4.0.6

ibm rational rhapsody design manager 4.0.7

ibm rational rhapsody design manager 4.0.1

ibm rational rhapsody design manager 4.0.2

ibm rational rhapsody design manager 4.0.3

ibm rational rhapsody design manager 5.0.2

ibm rational rhapsody design manager 6.0.0

ibm rational doors next generation 4.0.5

ibm rational doors next generation 4.0.6

ibm rational doors next generation 4.0.1

ibm rational doors next generation 4.0.2

ibm rational doors next generation 5.0.1

ibm rational doors next generation 5.0.2

ibm rational doors next generation 6.0.0

ibm rational doors next generation 4.0.0

ibm rational doors next generation 4.0.7

ibm rational doors next generation 5.0.0

ibm rational doors next generation 4.0.3

ibm rational doors next generation 4.0.4

ibm rational doors next generation 6.0.1

ibm rational doors next generation 6.0.2