Thursday, May 26, 2016

IBM Security Bulletin: Vulnerability in IBM® Java SDK affects multiple IBM Rational products based on IBM Jazz technology (CVE-2016-3427)

There is a vulnerability in IBM® SDK Java Technology Edition, Version 1.6 and 1.7 that are used by IBM Jazz Team Server affecting the following IBM Jazz Team Server based Applications: Collaborative Lifecycle Management (CLM), Rational Requirements Composer (RRC), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM). These issues were disclosed as part of the IBM Java SDK updates in April 2016.

CVE(s): CVE-2016-3427

Affected product(s) and affected version(s):

Rational Collaborative Lifecycle Management 3.0.1 – 6.0.2

Rational Quality Manager 2.0 – 2.0.1
Rational Quality Manager 3.0 – 3.0.1.6
Rational Quality Manager 4.0 – 4.0.7
Rational Quality Manager 5.0 – 5.0.2
Rational Quality Manager 6.0 – 6.0.2

Rational Team Concert 2.0 – 2.0.0.2
Rational Team Concert 3.0 – 3.0.6
Rational Team Concert 4.0 – 4.0.7
Rational Team Concert 5.0 – 5.0.2
Rational Team Concert 6.0 – 6.0.2

Rational Requirements Composer 2.0 – 2.0.0.4
Rational Requirements Composer 3.0 – 3.0.1.6
Rational Requirements Composer 4.0 – 4.0.7

Rational DOORS Next Generation 4.0 – 4.0.7
Rational DOORS Next Generation 5.0 – 5.0.2
Rational DOORS Next Generation 6.0 – 6.0.2

Rational Engineering Lifecycle Manager 1.0- 1.0.0.1
Rational Engineering Lifecycle Manager 4.0.3 – 4.0.7
Rational Engineering Lifecycle Manager 5.0 – 5.0.2
Rational Engineering Lifecycle Manager 6.0 – 6.0.2

Rational Rhapsody Design Manager 3.0 – 3.0.1
Rational Rhapsody Design Manager 4.0 – 4.0.7
Rational Rhapsody Design Manager 5.0 – 5.0.2
Rational Rhapsody Design Manager 6.0 – 6.0.2

Rational Software Architect Design Manager 3.0 – 3.0.1
Rational Software Architect Design Manager 4.0 – 4.0.7
Rational Software Architect Design Manager 5.0 – 5.0.2
Rational Software Architect Design Manager 6.0 – 6.0.2

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/1TXkjXP
X-Force Database: http://ift.tt/1N2N48r



from IBM PSIRT Blog http://ift.tt/1WWcw32

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.