Lucene search

K
ibmIBM7BBEA0E217A45AD2C675A6E05A34C2974CA97E6B37DFF59451B79D029CD3C4D6
HistoryJun 17, 2018 - 4:55 a.m.

Security Bulletin: Rational Systems Tester is affected by Libxml2 vulnerability (CVE-2014-0191)

2018-06-1704:55:54
www.ibm.com
15

0.024 Low

EPSS

Percentile

89.9%

Summary

Denial-Of-service vulnerability has been discovered in Libxml2 that was reported on May 09, 2014

Vulnerability Details

| Subscribe to My Notifications to be notified of important product support alerts like this.

  • Follow this link for more information (requires login with your IBM ID)
    —|—

CVE-ID: CVE-2014-0191

Description: Libxml2 is vulnerable to a denial of service, caused by the expansion of internal entities within the xmlParserHandlePEReference() function.

CVSS Base Score: 5 CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/93092&gt; for more information CVSS Environmental Score*****: Undefined CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P)

Affected Products and Versions

3.3, 3.3.0.1, 3.3.0.2, 3.3.0.3, 3.3.0.4, 3.3.0.5, 3.3.0.6, 3.3.0.7

Remediation/Fixes

Upgrade to Rational Systems Tester Interim Fix 1 for 3.3.0.7.
Rational Systems Tester (3.3.0.7.iFix1, Windows)
Rational Systems Tester (3.3.0.7.iFix1, Linux)
Rational Systems Tester (3.3.0.7.iFix1, Solaris)

Workarounds and Mitigations

None