Lucene search

K
ibmIBM0C672C2CC5F0C1F5FBB6D9826D4536D926D2BDDFD1227AF7577FD7287592B75C
HistoryFeb 12, 2020 - 4:09 p.m.

Security Bulletin: OpenSSL vulnerability affects IBM Rational Team Concert

2020-02-1216:09:02
www.ibm.com
11

0.015 Low

EPSS

Percentile

87.1%

Summary

OpenSSL has a security vulnerability that allows a remote attacker to exploit the application. OpenSSL is used by Rational BuildForge Agent shipped with IBM Rational Team Concert. Rational BuildForge has addressed the applicable CVE.

Vulnerability Details

CVEID:CVE-2019-1552
**DESCRIPTION:**OpenSSL could allow a local attacker to bypass security restrictions, caused by the building of . mingw programs or Windows programs with world writable path defaults. An attacker could exploit this vulnerability to modify default configuration, insert CA certificates, modify (or even replace) existing engine modules.
CVSS Base score: 2.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/164498 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
RTC 6.0.2
RTC 6.0.6.1
RTC 6.0.6

Remediation/Fixes

Follow the steps on Security Bulletin: Multiple vulnerabilities identified in OpenSSL affect Rational Build Forge (CVE-2019-1547, CVE-2019-1549, CVE-2019-1552, and CVE-2019-1563) to get the fixed version of Rational Build Forge Agent.

Workarounds and Mitigations

None