IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1 and 4.0 before 4.0.7 iFix10 allow remote authenticated users with access to lifecycle projects to obtain sensitive information by sending a crafted URL to the Lifecycle Query Engine. IBM X-Force ID: 108619.
| Software | From | Fixed in |
|---|---|---|
| ibm / rational_engineering_lifecycle_manager | 3.0 | 3.0.1.6.x |
| ibm / rational_engineering_lifecycle_manager | 4.0 | 4.0.7.x |