Lucene search

K
ibmIBM8F3BCABF9C26BADA69BCA298B34F516A2F69E4031C2BD8FFC25D0C2D6FDFA80B
HistoryApr 28, 2021 - 6:35 p.m.

Security Bulletin: Clickjack vulnerability affects multiple IBM Rational products based on IBM Jazz technology (CVE-2015-1928)

2021-04-2818:35:50
www.ibm.com
10
ibm jazz foundation
clickjack vulnerability
remote attacker hijack
rational collaborative lifecycle management
rational quality manager
rational team concert
rational requirements composer
rational doors next generation
rational engineering lifecycle manager
rational rhapsody design manager
rational software architect
cve-2015-1928
upgrade to 6.0.0 ifix4

EPSS

0.001

Percentile

49.8%

Summary

A vulnerability in the IBM Jazz Foundation affects the following IBM Jazz Team Server based Applications: Collaborative Lifecycle Management (CLM), Rational Requirements Composer (RRC), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM).

Vulnerability Details

CVEID: CVE-2015-1928**
DESCRIPTION:** IBM Jazz Foundation Collaborative Lifecycle Management could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could send a specially-crafted HTTP request to hijack the victim’s click actions from the system.
CVSS Base Score: 3.5
CVSS Temporal Score: See _<https://exchange.xforce.ibmcloud.com/vulnerabilities/102964&gt;_ for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

Affected Products and Versions

Rational Collaborative Lifecycle Management 3.0.1 - 6.0.0

Rational Quality Manager 3.0 - 3.0.1.6
Rational Quality Manager 4.0 - 4.0.7
Rational Quality Manager 5.0 - 5.0.2
Rational Quality Manager 6.0

Rational Team Concert 3.0 - 3.0.6
Rational Team Concert 4.0 - 4.0.7
Rational Team Concert 5.0 - 5.0.2
Rational Team Concert 6.0

Rational Requirements Composer 3.0 - 3.0.1.6
Rational Requirements Composer 4.0 - 4.0.7

Rational DOORS Next Generation 4.0 - 4.0.7
Rational DOORS Next Generation 5.0 - 5.0.2
Rational DOORS Next Generation 6.0

Rational Engineering Lifecycle Manager 4.0.3 - 4.0.7
Rational Engineering Lifecycle Manager 5.0 - 5.0.2
Rational Engineering Lifecycle Manager 6.0

Rational Rhapsody Design Manager 4.0 - 4.0.7
Rational Rhapsody Design Manager 5.0 - 5.0.2
Rational Rhapsody Design Manager 6.0

Rational Software Architect Design Manager 4.0 - 4.0.7
Rational Software Architect Design Manager 5.0 - 5.0.2
Rational Software Architect Design Manager 6.0

Remediation/Fixes

For the 6.x releases, upgrade to version 6.0.0 iFix4 or later

For the 3.x releases upgrade to version 3.0.1.6 iFix 7 or later (for CLM, upgrade the 3 individual products)

For any prior versions of the products listed above, IBM recommends upgrading to a fixed, supported version/release/platform of the product.

Workarounds and Mitigations

None

EPSS

0.001

Percentile

49.8%

Related for 8F3BCABF9C26BADA69BCA298B34F516A2F69E4031C2BD8FFC25D0C2D6FDFA80B