Lucene search

K
ibmIBM6B1C6EAA2CD3518A682D3056E09D4E1EA74C23C47C9F526F46AB4741F8D3E72F
HistoryApr 28, 2021 - 6:35 p.m.

Security Bulletin: Security vulnerability in Apache Tomcat affects multiple IBM Rational products based on IBM's Jazz technology

2021-04-2818:35:50
www.ibm.com
45
apache tomcat
security vulnerability
ibm rational
jazz technology
cross-site scripting
remote attacker
vulnerable products
cve-2019-0221
clm
rdng
relm
rtc
rqm
rhapsody dm
rsa dm
cookie-based authentication
product versions
remediation
latest ifix

EPSS

0.011

Percentile

84.5%

Summary

The Jazz Team Server is shipped with/or supports versions of the Apache Tomcat web server which contains a security vulnerability that could potentially impact the following IBM Rational products deployed on Apache Tomcat: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect Design Manager (RSA DM).

Vulnerability Details

CVEID: CVE-2019-0221 DESCRIPTION: Apache Tomcat is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the SSI printenv command. A remote attacker could exploit this vulnerability to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVSS Base Score: 6.1
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/161746&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

Rational Collaborative Lifecycle Management 6.0 - 6.0.6,1

Rational Quality Manager 6.0 - 6.0.6.1
Rational Team Concert 6.0 - 6.0.6.1
Rational DOORS Next Generation 6.0 - 6.0.6.1
Rational Engineering Lifecycle Manager 6.0 - 6.0.6.1
Rational Rhapsody Design Manager 6.0 - 6.0.6.1
Rational Software Architect Design Manager 6.0 - 6.0.1

Remediation/Fixes

Step 1.
Apply the latest ifix to your installed product version:

For the 6.0 - 6.0.6 releases:

Step 2:
Upgrade your Apache Tomcat to version 7.0.94 or later. Perform How to update the Apache Tomcat server for IBM Rational products based on versions 3.0.1.6, 4.0.7 or later of IBM’s Jazz technology to apply the remediation.

For any prior versions of the products listed above, IBM recommends upgrading to a fixed, supported version/release/platform of the product.

If the iFix is not found in the Fix Portal please contact IBM Support.

Workarounds and Mitigations

None