多款IBM Rational产品Jazz Help System信息泄露漏洞
漏洞描述
IBM Rational CLM、Rational Team Concert(RTC)和Rational Engineering Lifecycle Manager都是协作化生命周期管理解决方案;Rational Quality Manager(RQM)是一套协作的、基于Web的质量管理解决方案;Rational Requirements Composer和Rational DOORS Next Generation都是需求管理解决方案。
多款IBM Rational产品的IBM Jazz Help System中存在信息泄露漏洞,允许远程攻击者利用漏洞提交特殊的请求获取JSP文件中的源代码。
影响范围
IBM Rational Quality Manager 4.0 - 4.0.7
IBM Collaborative Lifecycle Management 4.0 - 5.0.2
IBM Rational Quality Manager 5.0 - 5.0.2
IBM Rational Requirements Composer 4.0 - 4.0.7
IBM Rational DOORS Next Generation 4.0 - 4.0.7
IBM Rational DOORS Next Generation 5.0 - 5.0.2
IBM Rational Engineering Lifecycle Manager 4.0.3 - 4.0.7
IBM Rational Engineering Lifecycle Manager 5.0 - 5.0.2
IBM Rational Rhapsody Design Manager 4.0 - 4.0.7
IBM Rational Rhapsody Design Manager 5.0 - 5.0.2
IBM Rational Software Architect Design Manager 4.0 - 4.0.7
IBM Rational Software Architect Design Manager 5.0 - 5.0.2
漏洞详情
暂无
漏洞 POC
暂无
修复建议
用户可参考如下厂商提供的安全公告获取补丁以修复该漏洞: