CVE-2015-7484: IBM Rational Engineering Lifecycle Manager

Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.

IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1 and 4.0 before 4.0.7 iFix10 allow remote authenticated users with access to lifecycle projects to obtain sensitive information by sending a crafted URL to the Lifecycle Query Engine. IBM X-Force ID: 108619.

Affected products

  • IBM Rational Engineering Lifecycle Manager: from 3.0, up to and including 3.0.1.6; from 4.0, up to and including 4.0.7

Published 2018-01-16. Last modified 2026-06-17.