Local Privilege Escalation Vulnerability (CVE-2015-0121) for multiple IBM products)
Local Privilege Escalation Vulnerability (CVE-2015-0121) for multiple IBM products)
Release date:
Updated on:
Affected Systems:
IBM Rational Requirements Composer 4.0-4.0.7
IBM Rational Requirements Composer 3.0-3.0.1.6
Description:
Bugtraq id: 74910
CVE (CAN) ID: CVE-2015-0121
IBM manufactures and sells computer hardware and software and provides consulting services for system architecture and network hosting.
IBM Rational Requirements Composer 3.0-3.0.1.6, 4.0-4.0.7, Rational DOORS Next Generation (RDNG) 4.0-4.0.7, 5.0-5.0.2, after LTPA single-point logon for WebSphere Application Server, when the LTPA token expires, the RM session is not interrupted. This allows remote attackers to exploit this vulnerability to obtain access permissions through an unattended workstation.
<* Source: IBM ([email protected])
*>
Suggestion:
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www-01.ibm.com/support/docview.wss? Uid = swg24253761
This article permanently updates the link address: