VulnerabilityModified
CVE-2016-6028
IBM Jazz technology based products might allow an attacker to view work item titles that they do not have privilege to view.
MEDIUM 4.3EPSS 0.77%
Does this matter?
Lower severity and a low EPSS score (0.77%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Jazz technology based products might allow an attacker to view work item titles that they do not have privilege to view.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.77% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/rational collaborative lifecycle management
- Source
- psirt@us.ibm.com
References
- http://www.securityfocus.com/bid/95111Third Party Advisory, VDB Entry
- https://www.ibm.com/support/docview.wss?uid=swg21996097Patch, Vendor Advisory
- http://www.securityfocus.com/bid/95111Third Party Advisory, VDB Entry
- https://www.ibm.com/support/docview.wss?uid=swg21996097Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.