Lucene search

K
ibmIBM740509E7B596C640F64D4262514363B544BEED503296DC01370E5145D40CF5D7
HistoryApr 28, 2021 - 6:35 p.m.

Security Bulletin: Vulnerabilities affects multiple IBM Rational products based on IBM Jazz technology (CVE-2015-4962, CVE-2015-4946)

2021-04-2818:35:50
www.ibm.com
4
ibm rational
jazz technology
vulnerabilities
authenticated users
unauthorized actions
sensitive information

EPSS

0.001

Percentile

41.1%

Summary

A vulnerability in the IBM Lifecycle Project Administrator and in the IBM Jazz Foundation affects the following IBM Jazz Team Server based Applications: Collaborative Lifecycle Management (CLM), Rational Requirements Composer (RRC), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM).

Vulnerability Details

CVEID: CVE-2015-4946**
DESCRIPTION:** IBM Rational LifeCycle Project Administration could allow an authenticated attacker to perform actions that they should not have permission.
CVSS Base Score: 3.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104876 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)

CVEID: CVE-2015-4962**
DESCRIPTION:** IBM Jazz Foundation could allow an authenticated user to view all the project areas which could contain sensitive information, due to insecure permissions.
CVSS Base Score: 3.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/105514 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Rational Collaborative Lifecycle Management 3.0.1 - 6.0.0

Rational Quality Manager 3.0 - 3.0.1.6
Rational Quality Manager 4.0 - 4.0.7
Rational Quality Manager 5.0 - 5.0.2
Rational Quality Manager 6.0

Rational Team Concert 3.0 - 3.0.6
Rational Team Concert 4.0 - 4.0.7
Rational Team Concert 5.0 - 5.0.2
Rational Team Concert 6.0

Rational Requirements Composer 3.0 - 3.0.1.6
Rational Requirements Composer 4.0 - 4.0.7

Rational DOORS Next Generation 4.0 - 4.0.7
Rational DOORS Next Generation 5.0 - 5.0.2
Rational DOORS Next Generation 6.0

Rational Engineering Lifecycle Manager 4.0.3 - 4.0.7
Rational Engineering Lifecycle Manager 5.0 - 5.0.2
Rational Engineering Lifecycle Manager 6.0

Rational Rhapsody Design Manager 4.0 - 4.0.7
Rational Rhapsody Design Manager 5.0 - 5.0.2
Rational Rhapsody Design Manager 6.0

Rational Software Architect Design Manager 4.0 - 4.0.7
Rational Software Architect Design Manager 5.0 - 5.0.2
Rational Software Architect Design Manager 6.0

Remediation/Fixes

For the 6.x releases, upgrade to version 6.0.1 or later from jazz.net or from PassPort Advantage

For the 3.x releases upgrade to version 3.0.1.6 iFix7 or later (for CLM, upgrade the 3 individual products)

For any prior versions of the products listed above, IBM recommends upgrading to a fixed, supported version/release/platform of the product.

Workarounds and Mitigations

None

EPSS

0.001

Percentile

41.1%

Related for 740509E7B596C640F64D4262514363B544BEED503296DC01370E5145D40CF5D7