A high risk vulnerability has been identified in the Jazz Team Server affecting some applications which use the Jazz Team Server. Rational Software Architect Design Manager and Rational Rhapsody Design Manager are affected applications. The exposure would allow a remote attacker to execute arbitrary code on the server.
| Subscribe to My Notifications to be notified of important product support alerts like this.
CVE ID: CVE-2014-0862 **
Description**: An unspecified vulnerability in Jazz Team Server allows remote attackers to execute arbitrary code on the server. The potentially malicious code being executed could compromise the integrity, confidentiality and availability of the server. **
CVSS Base Score:10
CVSS Temporal Score:See _<https://exchange.xforce.ibmcloud.com/vulnerabilities/90895>_ for the current score
CVSS Environmental Score*:Undefined
CVSS Vector:** (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Rational Software Architect Design Manager 3.0, 3.0.0.1, 3.0.1
Rational Software Architect Design Manager 4.0 - 4.0.5
Rational Rhapsody Design Manager 3.0, 3.0.0.1, 3.0.1
Rational Rhapsody Design Manager 4.0 - 4.0.5
For the 4.x releases of Rational Software Architect Design Manager upgrade to version 4.0.6:
RationalSoftware Architect Design Manager 4.0.6
For the 4.x releases of Rational Rhapsody Design Manager upgrade to version 4.0.6:
RationalRhapsody Design Manager 4.0.6
If you are unable to upgrade, apply the workaround listed below. If you have questions, contact IBM support for additional details on the fix.
For the 3.x releases of Rational Software Architect Design Manager and Rational Rhapsody Design Manager, apply the workaround listed below. If you have questions, contact IBM support for additional details on the fix.
Refer to the instructions in the following technote (as described for the Rational CLM products) to remove this vulnerability.
_
_How to block the Install URL
Note: In addition to the list of .war files in the above technote, you must also apply the steps for these additional files: