CVE-2021-29786: Medium severity IBM Engineering Lifecycle Optimization vulnerability
IBM Jazz Foundation stores user credentials in clear text which can be read by an authenticated user.
Other sources
IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-29786.
What is the severity level of CVE-2021-29786?
The severity level of CVE-2021-29786 is medium.
What software products are affected by CVE-2021-29786?
The affected software products are IBM Engineering Lifecycle Optimization 7.0, IBM Engineering Workflow Management 7.0, IBM Rational Collaborative Lifecycle Management 6.0.6, IBM Rational DOORS Next Generation 6.0.6 and 7.0, IBM Rational Engineering Lifecycle Manager 7.0, and IBM Rational Team Concert 6.0.2 and 6.0.6.
How can an authenticated user exploit CVE-2021-29786?
An authenticated user can exploit CVE-2021-29786 by reading user credentials that are stored in clear text.
Is there a fix available for CVE-2021-29786?
Yes, IBM has released a fix for CVE-2021-29786. Please refer to the IBM Security Bulletin for more information.