Lucene search

K
ibmIBM59BDD6369B4197C0765797F07CD778FCA7DBE028895E47FE70153F58B63A0148
HistoryJun 17, 2018 - 5:20 a.m.

Security Bulletin: Multiple vulnerabilities affect Rational Rhapsody Design Manager with potential for security attacks

2018-06-1705:20:01
www.ibm.com
14

EPSS

0.003

Percentile

67.9%

Summary

IBM Rhapsody Design Manager is affected by multiple vulnerabilities with potential for evil file upload, cross site scripting, HTML injection, JSON Hijacking and XML entity expansion.

Vulnerability Details

CVEID: CVE-2016-8973**
DESCRIPTION:** IBM Rhapsody DM contains an undisclosed vulnerability that may allow an authenticated user to upload infected malicious files to the server.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/118910 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)

CVEID: CVE-2016-9694**
DESCRIPTION:** IBM Rhapsody DM is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Base Score: 5.4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/119518 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)

CVEID: CVE-2016-9696**
DESCRIPTION:** IBM Rhapsody DM is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim’s Web browser within the security context of the hosting site.
CVSS Base Score: 5.4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/119520 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)

CVEID: CVE-2016-9697**
DESCRIPTION:** An unspecified vulnerability in IBM Rhapsody DM could allow an attacker to perform a JSON Hijacking Attack. A JSON Hijacking Attack may expose to an attacker information passed between the server and the browser.
CVSS Base Score: 3.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/119521 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N)

CVEID: CVE-2016-9698**
DESCRIPTION:** IBM Rhapsody DM is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.
CVSS Base Score: 7.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/119522 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L)

Affected Products and Versions

Rational Rhapsody Design Manager 4.0 - 4.0.7
Rational Rhapsody Design Manager 5.0 - 5.0.2
Rational Rhapsody Design Manager 6.0 - 6.0.3

Remediation/Fixes

For the 6.0.3 releases, upgrade to version 6.0.3 ifix2 or later
<https://jazz.net/downloads/design-management/releases/6.0.3iFix2&gt;
For the 6.0.2 releases, upgrade to version 6.0.2 ifix8 or later
<https://jazz.net/downloads/design-management/releases/6.0.2iFix8&gt;
For the 5.x releases, upgrade to version 5.0.2 iFix19 or later
<https://jazz.net/downloads/design-management/releases/5.0.2iFix19&gt;

Workarounds and Mitigations

For 4.0.7 and any prior versions of the products listed above, IBM recommends upgrading to 5.0.2, or 6.0.2 or 6.0.3.

EPSS

0.003

Percentile

67.9%

Related for 59BDD6369B4197C0765797F07CD778FCA7DBE028895E47FE70153F58B63A0148