IBM Rational Engineering Lifecycle Manager, Rational Software Architect Design Manager and Rational Rhapsody Design Manager are vulnerable to a cross-site request forgery attack.
| Subscribe to My Notifications to be notified of important product support alerts like this.
CVE ID: CVE-2014-3037 **
Description**: Rational Engineering Lifecycle Manager, Rational Software Architect Design Manager, and Rhapsody Design Manager use the component IBM Configuration Management Application (VVC), which is vulnerable to cross-site request forgery, caused by improper validation of user-supplied data. By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities. **
CVSS Base Score:** 3.5**
CVSS Temporal Score:See <https://exchange.xforce.ibmcloud.com/vulnerabilities/93303> for the current score
CVSS Environmental Score*:Undefined
CVSS Vector:** (AV:N/AC:M/Au:S/C:N/I:P/A:N)
Rational Engineering Lifecycle Manager 1.0, 1.0.0.1, 4.0.3, 4.0.4, 4.0.5, 4.0.6, 5.0
Rational Software Architect Design Manager 3.0, 3.0.0.1, 3.0.1, 4.0 - 4.0.6, 5.0
Rational Rhapsody Design Manager 3.0, 3.0.0.1, 3.0.1, 4.0 - 4.0.6, 5.0
For Rational Engineering Lifecycle Manager:
or
For Rational Software Architect Design Manager:
or
For Rational Rhapsody Design Manager:
or
For the 1.x releases of Rational Engineering Lifecycle Manager, the 3.x releases of Rational Software Architect Design Manager and Rhapsody Design Manager, or customers who cannot upgrade to 4.0.7 or 5.0.1, please contact IBM support for guidance.
None