CVE-2015-0121
Last modified
CVE-2015-0121 is a vulnerability of currently unknown severity. IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next Generation (RDNG) 4.0 through 4.0.7 and 5.0 through 5.0.2, when LTPA single sign on is used with WebSphere Application Server, do not terminate a Requirements Management (RM) session upon LTPA token expiration, which allows remote attackers to obtain access by leveraging an unattended workstation.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next Generation (RDNG) 4.0 through 4.0.7 and 5.0 through 5.0.2, when LTPA single sign on is used with WebSphere Application Server, do not terminate a Requirements Management (RM) session upon LTPA token expiration, which allows remote attackers to obtain access by leveraging an unattended workstation.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Rational Requirements Composer | 3.0 |
| Ibm | Rational Requirements Composer | 3.0.1 |
| Ibm | Rational Requirements Composer | 3.0.1.1 |
| Ibm | Rational Requirements Composer | 3.0.1.2 |
| Ibm | Rational Requirements Composer | 3.0.1.3 |
| Ibm | Rational Requirements Composer | 3.0.1.4 |
| Ibm | Rational Requirements Composer | 3.0.1.5 |
| Ibm | Rational Requirements Composer | 3.0.1.6 |
| Ibm | Rational Requirements Composer | 4.0 |
| Ibm | Rational Requirements Composer | 4.0.0 |
| Ibm | Rational Requirements Composer | 4.0.0.1 |
| Ibm | Rational Requirements Composer | 4.0.0.2 |
| Ibm | Rational Requirements Composer | 4.0.1 |
| Ibm | Rational Requirements Composer | 4.0.2 |
| Ibm | Rational Requirements Composer | 4.0.3 |
| Ibm | Rational Requirements Composer | 4.0.4 |
| Ibm | Rational Requirements Composer | 4.0.5 |
| Ibm | Rational Requirements Composer | 4.0.6 |
| Ibm | Rational Requirements Composer | 4.0.7 |
| Ibm | Rational Doors Next Generation | 4.0.0 |
| Ibm | Rational Doors Next Generation | 4.0.1 |
| Ibm | Rational Doors Next Generation | 4.0.2 |
| Ibm | Rational Doors Next Generation | 4.0.3 |
| Ibm | Rational Doors Next Generation | 4.0.4 |
| Ibm | Rational Doors Next Generation | 4.0.5 |
| Ibm | Rational Doors Next Generation | 4.0.6 |
| Ibm | Rational Doors Next Generation | 4.0.7 |
| Ibm | Rational Doors Next Generation | 5.0 |
| Ibm | Rational Doors Next Generation | 5.0.1 |
| Ibm | Rational Doors Next Generation | 5.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-0121?
How severe is CVE-2015-0121?
How do I fix CVE-2015-0121?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-0115Cross-site request forgery (CSRF) vulnerability in IBM Leads…
- CVE-2015-0116IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.…
- CVE-2015-0117The LDAP Server in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and…
- CVE-2015-0118IBM WebSphere Message Broker Toolkit 7 before 7007 IF2 and 8…
- CVE-2015-0119FastBack Mount in IBM Tivoli Storage Manager FastBack 6.1.x …
- CVE-2015-0120Buffer overflow in the FastBackMount process in IBM Tivoli S…
- CVE-2015-0122Cross-site scripting (XSS) vulnerability in IBM Rational Tea…
- CVE-2015-0123Cross-site scripting (XSS) vulnerability in IBM Rational Tea…
- CVE-2015-0124Cross-site scripting (XSS) vulnerability in IBM Rational Qua…
- CVE-2015-0125Cross-site scripting (XSS) vulnerability in IBM Rational DOO…
- CVE-2015-0126IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.…
- CVE-2015-0127IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.…
Are you affected by CVE-2015-0121?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
